2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27260 | HIGH | 7.5 | 0.2% | Mar 25, 2026 | Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains an Improper Filtering of Special Elements vulnerability ... |
| CVE-2025-43534 | MEDIUM | 6.8 | 0.2% | Mar 25, 2026 | A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 2... |
| CVE-2025-33254 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause internal state corruption. A success... |
| CVE-2025-33248 | HIGH | 7.8 | 0.2% | Mar 24, 2026 | NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convin... |
| CVE-2025-33247 | HIGH | 7.8 | 0.3% | Mar 24, 2026 | NVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code executi... |
| CVE-2025-33244 | CRITICAL | 9 | 0.6% | Mar 24, 2026 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted... |
| CVE-2025-33242 | MEDIUM | 5.9 | 0.3% | Mar 24, 2026 | NVIDIA B300 MCU contains a vulnerability in the CX8 MCU that could allow a malicious actor to modify unsupported registr... |
| CVE-2025-33238 | HIGH | 7.5 | 0.3% | Mar 24, 2026 | NVIDIA Triton Inference Server Sagemaker HTTP server contains a vulnerability where an attacker may cause an exception. ... |
| CVE-2025-33216 | MEDIUM | 6.8 | 0.3% | Mar 24, 2026 | NVIDIA SNAP-4 Container contains a vulnerability in the configuration interface where an attacker on a VM may cause an i... |
| CVE-2025-33215 | MEDIUM | 6.8 | 0.3% | Mar 24, 2026 | NVIDIA SNAP-4 Container contains a vulnerability in the VIRTIO-BLK component where a malicious guest VM may cause use of... |
| CVE-2025-11571 | LOW | 2.1 | 0.4% | Mar 24, 2026 | Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The comm... |
| CVE-2025-71275 | — | — | — | Mar 24, 2026 | Rejected reason: This CVE was rejected due to being a duplicate of CVE-2024-45519. |
| CVE-2025-64998 | HIGH | 7.2 | 0.3% | Mar 24, 2026 | Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site wi... |
| CVE-2025-41660 | HIGH | 8.8 | 0.4% | Mar 24, 2026 | A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enab... |
| CVE-2025-60949 | HIGH | 7.5 | 0.4% | Mar 23, 2026 | Census CSWeb 8.0.1 allows "app/config" to be reachable via HTTP in some deployments. A remote, unauthenticated attacker ... |
| CVE-2025-60948 | MEDIUM | 5.4 | 0.2% | Mar 23, 2026 | Census CSWeb 8.0.1 allows stored cross-site scripting in user supplied fields. A remote, authenticated attacker could st... |
| CVE-2025-60947 | HIGH | 8.8 | 0.5% | Mar 23, 2026 | Census CSWeb 8.0.1 allows arbitrary file upload. A remote, authenticated attacker could upload a malicious file, possibl... |
| CVE-2025-60946 | HIGH | 8.8 | 0.5% | Mar 23, 2026 | Census CSWeb 8.0.1 allows arbitrary file path input. A remote, authenticated attacker could access unintended file direc... |
| CVE-2025-52204 | MEDIUM | 6.1 | 0.3% | Mar 23, 2026 | A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerI... |
| CVE-2025-15606 | HIGH | 7.5 | 0.3% | Mar 23, 2026 | A Denial-of-Service (DoS) vulnerability in the httpd component of TP-Link's TD-W8961N v4.0 due to improper input sanitiz... |
| CVE-2025-15605 | HIGH | 7.3 | 0.1% | Mar 23, 2026 | A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables... |
| CVE-2025-15519 | HIGH | 7.2 | 0.6% | Mar 23, 2026 | Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600... |
| CVE-2025-15518 | HIGH | 7.2 | 0.6% | Mar 23, 2026 | Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600... |
| CVE-2025-15517 | HIGH | 8.1 | 3.1% | Mar 23, 2026 | A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoin... |
| CVE-2025-41008 | CRITICAL | 9.3 | 0.2% | Mar 23, 2026 | SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now