2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-27260HIGH7.5Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability ...
CVE-2025-43534MEDIUM6.8A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 2...
CVE-2025-33254HIGH7.5NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A success...
CVE-2025-33248HIGH7.8NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convin...
CVE-2025-33247HIGH7.8NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code executi...
CVE-2025-33244CRITICAL9NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted...
CVE-2025-33242MEDIUM5.9NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr...
CVE-2025-33238HIGH7.5NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. ...
CVE-2025-33216MEDIUM6.8NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an i...
CVE-2025-33215MEDIUM6.8NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of...
CVE-2025-11571LOW2.1Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The comm...
CVE-2025-71275——Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519.
CVE-2025-64998HIGH7.2Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site wi...
CVE-2025-41660HIGH8.8A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enab...
CVE-2025-60949HIGH7.5Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker ...
CVE-2025-60948MEDIUM5.4Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could st...
CVE-2025-60947HIGH8.8Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibl...
CVE-2025-60946HIGH8.8Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file direc...
CVE-2025-52204MEDIUM6.1A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerI...
CVE-2025-15606HIGH7.5A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitiz...
CVE-2025-15605HIGH7.3A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables...
CVE-2025-15519HIGH7.2Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600...
CVE-2025-15518HIGH7.2Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600...
CVE-2025-15517HIGH8.1A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoin...
CVE-2025-41008CRITICAL9.3SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now