2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15344 | HIGH | 8.8 | 0.3% | Jan 29, 2026 | Tanium addressed a SQL injection vulnerability in Asset. |
| CVE-2025-71007 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | An input validation vulnerability in the oneflow.index_add component of OneFlow v0.9.0 allows attackers to cause a Denia... |
| CVE-2025-71003 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | An input validation vulnerability in the flow.arange() component of OneFlow v0.9.0 allows attackers to cause a Denial of... |
| CVE-2025-68119 | HIGH | 7 | 0.3% | Jan 28, 2026 | Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercuria... |
| CVE-2025-61731 | HIGH | 7.8 | 0.5% | Jan 28, 2026 | Building a malicious file with cmd/go can cause can cause a write to an attacker-controlled file with partial control of... |
| CVE-2025-61726 | HIGH | 7.5 | 1.9% | Jan 28, 2026 | The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query p... |
| CVE-2025-46691 | HIGH | 7.8 | 0.1% | Jan 28, 2026 | Dell PremierColor Panel Driver, versions prior to 1.0.0.1 A01, contains an Improper Access Control vulnerability. A low ... |
| CVE-2025-14840 | HIGH | 7.5 | 0.3% | Jan 28, 2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal HTTP Client Manager allows Forceful Browsin... |
| CVE-2025-14472 | HIGH | 8.1 | 0.1% | Jan 28, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia Content Hub allows Cross Site Request Forgery.This issu... |
| CVE-2025-13982 | HIGH | 8.1 | 0.1% | Jan 28, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Login Time Restriction allows Cross Site Request Forgery.This ... |
| CVE-2025-71000 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | An issue in the flow.cuda.BoolTensor component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via... |
| CVE-2025-70999 | HIGH | 7.5 | 0.5% | Jan 28, 2026 | A GPU device-ID validation flaw in the flow.cuda.get_device_capability() component of OneFlow v0.9.0 allows attackers to... |
| CVE-2025-65891 | HIGH | 7.5 | 0.6% | Jan 28, 2026 | A GPU device-ID validation flaw in OneFlow v0.9.0 allows attackers to trigger a Denial of Dervice (DoS) by invoking flow... |
| CVE-2025-57793 | HIGH | 8.6 | 0.3% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user... |
| CVE-2025-33220 | HIGH | 7.8 | 0.2% | Jan 28, 2026 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memor... |
| CVE-2025-33219 | HIGH | 7.8 | 0.2% | Jan 28, 2026 | NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an in... |
| CVE-2025-33218 | HIGH | 7.8 | 0.2% | Jan 28, 2026 | NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacke... |
| CVE-2025-33217 | HIGH | 7.8 | 0.2% | Jan 28, 2026 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successfu... |
| CVE-2025-65890 | HIGH | 7.5 | 0.5% | Jan 28, 2026 | A device-ID validation flaw in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) by calling flow.cuda.s... |
| CVE-2025-65889 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | A type validation flaw in the flow.dstack() component of OneFlow v0.9.0 allows attackers to cause a Denial of Service (D... |
| CVE-2025-65888 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | A dimension validation flaw in the flow.empty() component of OneFlow 0.9.0 allows attackers to cause a Denial of Service... |
| CVE-2025-65886 | HIGH | 7.5 | 0.4% | Jan 28, 2026 | A shape mismatch vulnerability in OneFlow v0.9.0 allows attackers to cause a Denial of Service (DoS) via supplying craft... |
| CVE-2025-13917 | HIGH | 7 | 0.1% | Jan 28, 2026 | WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereb... |
| CVE-2025-69517 | HIGH | 8.8 | 0.5% | Jan 28, 2026 | An HTML injection vulnerability in Amidaware Inc Tactical RMM v1.3.1 and earlier allows authenticated users to inject ar... |
| CVE-2025-58150 | HIGH | 8.8 | 0.1% | Jan 28, 2026 | Shadow mode tracing code uses a set of per-CPU variables to avoid cumbersome parameter passing. Some of these variables... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now