2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10963HIGH8.8A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. Affected is the function sub_4016F0 of the file /c...
CVE-2025-10962HIGH8.8A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This impacts the function sub_403198 of the file /cgi-b...
CVE-2025-60249MEDIUM6.4vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and user.py, by a user on a vulnerability-lookup instan...
CVE-2025-57623MEDIUM5.3A NULL pointer dereference in TOTOLINK N600R firmware v4.3.0cu.7866_B2022506 allows attackers to cause a Denial of Servi...
CVE-2025-48707HIGH7.5An issue was discovered in Stormshield Network Security (SNS) before 5.0.1. TPM authentication information could, in som...
CVE-2025-29155MEDIUM6.5An issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpoint
CVE-2025-10961HIGH8A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. This affects the function sub_4030C0 of the file /cgi-b...
CVE-2025-10960HIGH8.8A vulnerability was found in Wavlink NU516U1 M16U1_V240425. The impacted element is the function sub_402D1C of the file ...
CVE-2025-10959HIGH8.8A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. The affected element is the function sub_401778 of the ...
CVE-2025-10958HIGH8.8A flaw has been found in Wavlink NU516U1 M16U1_V240425. Impacted is the function sub_403010 of the file /cgi-bin/wireles...
CVE-2025-34227HIGH8.8Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL ...
CVE-2025-10880HIGH7.5All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allo...
CVE-2025-10879MEDIUM5.3All versions of Dingtian DT-R002 are vulnerable to an Insufficiently Protected Credentials vulnerability that could allo...
CVE-2025-60019LOW3.7glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memo...
CVE-2025-60018MEDIUM4.8glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out...
CVE-2025-59841CRITICAL9.8Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application i...
CVE-2025-57446HIGH7.5An issue in O-RAN Near Realtime RIC ric-plt-submgr in the J-Release environment, allows remote attackers to cause a deni...
CVE-2025-55560HIGH7.5An issue in pytorch v2.7.0 can lead to a Denial of Service (DoS) when a PyTorch model consists of torch.Tensor.to_sparse...
CVE-2025-55559HIGH7.5An issue was discovered TensorFlow v2.18.0. A Denial of Service (DoS) occurs when padding is set to 'valid' in tf.keras....
CVE-2025-55558HIGH7.5A buffer overflow occurs in pytorch v2.7.0 when a PyTorch model consists of torch.nn.Conv2d, torch.nn.functional.hardshr...
CVE-2025-55557HIGH7.5A Name Error occurs in pytorch v2.7.0 when a PyTorch model consists of torch.cummin and is compiled by Inductor, leading...
CVE-2025-55556MEDIUM6.5TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to unexpected behavior in t...
CVE-2025-55554MEDIUM5.3pytorch v2.8.0 was discovered to contain an integer overflow in the component torch.nan_to_num-.long().
CVE-2025-55553HIGH7.5A syntax error in the component proxy_tensor.py of pytorch v2.7.0 allows attackers to cause a Denial of Service (DoS).
CVE-2025-55552HIGH7.5pytorch v2.8.0 was discovered to display unexpected behavior when the components torch.rot90 and torch.randn_like are us...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now