2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-57156HIGH7.5NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through co...
CVE-2025-57155HIGH7.5NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a ...
CVE-2025-55131HIGH7.1A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using...
CVE-2025-33233HIGH7.8NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. ...
CVE-2025-33230HIGH7.3NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS comm...
CVE-2025-33229HIGH7.3NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitra...
CVE-2025-33228HIGH7.3NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command in...
CVE-2025-56353HIGH7.5In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), a memory leak occurs due to the broker's failu...
CVE-2025-33015HIGH8.8IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload by not validating the content of the file uploade...
CVE-2025-53912HIGH8.1An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A s...
CVE-2025-1722HIGH7.5IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ...
CVE-2025-1719HIGH7.5IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due ...
CVE-2025-15380HIGH7.2The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Fl...
CVE-2025-15347HIGH8.8The Creator LMS – The LMS for Creators, Coaches, and Trainers plugin for WordPress is vulnerable to unauthorized modific...
CVE-2025-14115HIGH8.4IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Inte...
CVE-2025-12985HIGH8.4IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalati...
CVE-2025-9466HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9465HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9464HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is tr...
CVE-2025-9283HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9282HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9281HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9280HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using ...
CVE-2025-9279HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the ...
CVE-2025-9278HIGH7.5A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Sui...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now