2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-57155HIGH7.5NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a ...
CVE-2025-55131HIGH7.1A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using...
CVE-2025-33233HIGH7.8NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. ...
CVE-2025-33230HIGH7.3NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS comm...
CVE-2025-33229HIGH7.3NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitra...
CVE-2025-33228HIGH7.3NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command in...
CVE-2025-56353HIGH7.5In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), a memory leak occurs due to the broker's failu...
CVE-2025-33015HIGH8.8IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploade...
CVE-2025-53912HIGH8.1An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A s...
CVE-2025-1722HIGH7.5IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ...
CVE-2025-1719HIGH7.5IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ...
CVE-2025-15380HIGH7.2The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Fl...
CVE-2025-15347HIGH8.8The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modific...
CVE-2025-14115HIGH8.4IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Inte...
CVE-2025-12985HIGH8.4IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalati...
CVE-2025-9466HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9465HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9464HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is tr...
CVE-2025-9283HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9282HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9281HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9280HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using ...
CVE-2025-9279HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9278HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Sui...
CVE-2025-15281HIGH7.5Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cau...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now