2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-14807MEDIUM6.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to HTTP header injection, caused by improper v...
CVE-2025-70888CRITICAL9.8An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the o...
CVE-2025-14790MEDIUM6.5IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information due ...
CVE-2025-12708MEDIUM5.5IBM Concert 1.0.0 through 2.2.0 contains hard-coded credentials that could be obtained by a local user.
CVE-2025-70952HIGH7.5pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling ...
CVE-2025-70887HIGH8.8An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and th...
CVE-2025-67030HIGH8.8Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d...
CVE-2025-69358HIGH7.5Missing Authorization vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Exploiting Incor...
CVE-2025-69347HIGH8.6Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploit...
CVE-2025-69096HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in G5Theme Zorka zork...
CVE-2025-14595MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.1...
CVE-2025-13436MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.8.7, 18.9 before 18.9.3, and 1...
CVE-2025-13078MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.10 before 18.8.7, 18.9 before 18.9.3, and ...
CVE-2025-59707CRITICAL9.8In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft becau...
CVE-2025-59706CRITICAL9.8In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.
CVE-2025-32991CRITICAL9In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
CVE-2025-40842MEDIUM6.1Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Scripting (XSS) vulnerability which, if exp...
CVE-2025-40841MEDIUM4.3Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a Cross-Site Request Forgery (CSRF) vulnerability which,...
CVE-2025-27260HIGH7.5Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability ...
CVE-2025-43534MEDIUM6.8A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 2...
CVE-2025-33254HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A success...
CVE-2025-33248HIGH7.8NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convin...
CVE-2025-33247HIGH7.8NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code executi...
CVE-2025-33244CRITICAL9NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted...
CVE-2025-33242MEDIUM5.9NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now