2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14807 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper v... |
| CVE-2025-70888 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the o... |
| CVE-2025-14790 | MEDIUM | 6.5 | 0.2% | Mar 25, 2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due ... |
| CVE-2025-12708 | MEDIUM | 5.5 | 0.1% | Mar 25, 2026 | IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user. |
| CVE-2025-70952 | HIGH | 7.5 | 0.9% | Mar 25, 2026 | pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling ... |
| CVE-2025-70887 | HIGH | 8.8 | 0.3% | Mar 25, 2026 | An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and th... |
| CVE-2025-67030 | HIGH | 8.8 | 0.7% | Mar 25, 2026 | Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d... |
| CVE-2025-69358 | HIGH | 7.5 | 0.3% | Mar 25, 2026 | Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor... |
| CVE-2025-69347 | HIGH | 8.6 | 0.4% | Mar 25, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploit... |
| CVE-2025-69096 | HIGH | 7.1 | 0.2% | Mar 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zork... |
| CVE-2025-14595 | MEDIUM | 4.3 | 0.3% | Mar 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.1... |
| CVE-2025-13436 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 1... |
| CVE-2025-13078 | MEDIUM | 6.5 | 0.4% | Mar 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and ... |
| CVE-2025-59707 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft becau... |
| CVE-2025-59706 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution. |
| CVE-2025-32991 | CRITICAL | 9 | 0.3% | Mar 25, 2026 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. |
| CVE-2025-40842 | MEDIUM | 6.1 | 0.1% | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exp... |
| CVE-2025-40841 | MEDIUM | 4.3 | 0.1% | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which,... |
| CVE-2025-27260 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability ... |
| CVE-2025-43534 | MEDIUM | 6.8 | 0.2% | Mar 25, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 2... |
| CVE-2025-33254 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A success... |
| CVE-2025-33248 | HIGH | 7.8 | 0.2% | Mar 24, 2026 | NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convin... |
| CVE-2025-33247 | HIGH | 7.8 | 0.3% | Mar 24, 2026 | NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code executi... |
| CVE-2025-33244 | CRITICAL | 9 | 0.6% | Mar 24, 2026 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted... |
| CVE-2025-33242 | MEDIUM | 5.9 | 0.3% | Mar 24, 2026 | NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now