2025 CVE Vulnerabilities

45,209 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23345MEDIUM4.4NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a...
CVE-2025-23332MEDIUM5NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger ...
CVE-2025-23330MEDIUM5.5NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer deref...
CVE-2025-23300MEDIUM5.5NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer d...
CVE-2025-11621HIGH8.1Vault and Vault Enterprise’s (“Vault”) AWS Auth method may be susceptible to authentication bypass if the role of the co...
CVE-2025-10937MEDIUM6.8Oxford Nanopore Technologies' MinKNOW software at or prior to version 24.11 creates a temporary file to store the local ...
CVE-2025-61464MEDIUM6.5gnuboard gnuboard4 v4.36.04 and before is vulnerable to Second-order SQL Injection via the search_table in bbs/search.ph...
CVE-2025-61413MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the /manager/pages component of Piranha CMS v12.0 allows attackers ...
CVE-2025-57240MEDIUM6.1Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows attackers to execute ar...
CVE-2025-62713HIGH7.2Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati...
CVE-2025-34156MEDIUM6.9Tibbo AggreGate Network Manager < 6.40.05 exposes sensitive system information through an unauthenticated endpoint at /c...
CVE-2025-34155MEDIUM6.9Tibbo AggreGate Network Manager < 6.40.05 contains an observable response discrepancy in its login functionality. Authen...
CVE-2025-62169HIGH8.1OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of th...
CVE-2025-59048HIGH8.1OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is v...
CVE-2025-50951MEDIUM6.5FontForge v20230101 was discovered to contain a memory leak via the utf7toutf8_copy function at /fontforge/sfd.c.
CVE-2025-50950HIGH7.5Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.
CVE-2025-50949MEDIUM6.5FontForge v20230101 was discovered to contain a memory leak via the component DlgCreate8.
CVE-2025-12114MEDIUM5.5Enabled serial console could potentially leak information that might help attacker to find vulnerabilities.This issue af...
CVE-2025-61136HIGH7.1A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attack...
CVE-2025-61132HIGH7.1A Host Header Injection vulnerability in the password reset component in levlaz braindump v0.4.14 allows remote attacker...
CVE-2025-56009MEDIUM5.3Cross site request forgery (CSRF) vulnerability in KeeneticOS before 4.3 at "/rci" API endpoint allows attackers to take...
CVE-2025-56008MEDIUM6.1Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows attackers located near t...
CVE-2025-56007MEDIUM6.5CRLF-injection in KeeneticOS before 4.3 at "/auth" API endpoint allows attackers to take over the device via adding addi...
CVE-2025-12110MEDIUM5.4A flaw was found in Keycloak. An offline session continues to be valid when the offline_access scope is removed from the...
CVE-2025-62256MEDIUM5.3Liferay Portal 7.4.0 through 7.4.3.109, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.7, 7.4 GA...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now