2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-33252HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...
CVE-2025-33251HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...
CVE-2025-33250HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...
CVE-2025-33249HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input ...
CVE-2025-33246HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause ...
CVE-2025-33245HIGH8.8NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl...
CVE-2025-33243HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed enviro...
CVE-2025-33241HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciou...
CVE-2025-33240HIGH7.8NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code i...
CVE-2025-33239HIGH7.8NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code inj...
CVE-2025-33236HIGH7.8NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A...
CVE-2025-14340HIGH7.3Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an ...
CVE-2025-13689HIGH8.8IBM DataStage on Cloud Pak for Data could allow an authenticated user to execute arbitrary commands and gain access to s...
CVE-2025-33088HIGH7.4IBM Concert 1.0.0 through 2.1.0 could allow a local user with specific knowledge about the system's architecture to esca...
CVE-2025-36379HIGH7.5IBM Security QRadar EDR 3.12 through 3.12.23 IBM Security ReaQta uses weaker than expected cryptographic algorithms that...
CVE-2025-36377HIGH8.8IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an...
CVE-2025-36376HIGH8.8IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an...
CVE-2025-70846HIGH7.1lty628 aidigu v1.9.1 is vulnerable to Cross Site Scripting (XSS) on the /tools/Password/add page in the input field pass...
CVE-2025-67102HIGH7.6A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to exec...
CVE-2025-32355HIGH7.9Rocket TRUfusion Enterprise through 7.10.4.0 uses a reverse proxy to handle incoming connections. However, the proxy is ...
CVE-2025-13108HIGH7.5IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in mem...
CVE-2025-36247HIGH8.2IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vul...
CVE-2025-67905HIGH8.7Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which...
CVE-2025-70828HIGH8.8An issue in Datart v1.0.0-rc.3 allows attackers to execute arbitrary code via the url parameter in the JDBC configuratio...
CVE-2025-70397HIGH7.2jizhicms 2.5.6 is vulnerable to SQL Injection in Article/deleteAll and Extmolds/deleteAll via the data parameter.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now