2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-33242MEDIUM5.9NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr...
CVE-2025-33238HIGH7.5NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. ...
CVE-2025-33216MEDIUM6.8NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an i...
CVE-2025-33215MEDIUM6.8NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of...
CVE-2025-11571LOW2.1Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The comm...
CVE-2025-71275Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.
CVE-2025-64998HIGH7.2Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site wi...
CVE-2025-41660HIGH8.8A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enab...
CVE-2025-60949HIGH7.5Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker ...
CVE-2025-60948MEDIUM5.4Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could st...
CVE-2025-60947HIGH8.8Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibl...
CVE-2025-60946HIGH8.8Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file direc...
CVE-2025-52204MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerI...
CVE-2025-15606HIGH7.5A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitiz...
CVE-2025-15605HIGH7.3A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables...
CVE-2025-15519HIGH7.2Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600...
CVE-2025-15518HIGH7.2Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600...
CVE-2025-15517HIGH8.1A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoin...
CVE-2025-41008CRITICAL9.3SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d...
CVE-2025-41007CRITICAL9.3SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through...
CVE-2025-6229MEDIUM6.4The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Tabl...
CVE-2025-13997MEDIUM5.3The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin f...
CVE-2025-10734MEDIUM5.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-10731MEDIUM5.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...
CVE-2025-10679HIGH7.3The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now