2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23348 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created b... |
| CVE-2025-23346 | LOW | 3.3 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereferen... |
| CVE-2025-23340 | LOW | 3.3 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b... |
| CVE-2025-23339 | HIGH | 7.8 | 0.3% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based bu... |
| CVE-2025-23338 | MEDIUM | 5.5 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write... |
| CVE-2025-23308 | HIGH | 7.8 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buff... |
| CVE-2025-23275 | HIGH | 7.1 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GP... |
| CVE-2025-23274 | MEDIUM | 4.5 | 0.1% | Sep 24, 2025 | NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a mali... |
| CVE-2025-23273 | MEDIUM | 4.7 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a di... |
| CVE-2025-23272 | MEDIUM | 5.7 | 0.1% | Sep 24, 2025 | NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially... |
| CVE-2025-23271 | LOW | 3.3 | 0.2% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b... |
| CVE-2025-23255 | LOW | 3.3 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-... |
| CVE-2025-23248 | LOW | 3.3 | 0.1% | Sep 24, 2025 | NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b... |
| CVE-2025-9353 | MEDIUM | 6.4 | 0.3% | Sep 24, 2025 | The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers... |
| CVE-2025-60020 | MEDIUM | 6.4 | 0.2% | Sep 24, 2025 | nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in p... |
| CVE-2025-10906 | HIGH | 8.4 | 0.2% | Sep 24, 2025 | A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:Wit... |
| CVE-2025-9054 | CRITICAL | 9.8 | 0.3% | Sep 24, 2025 | The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi... |
| CVE-2025-39890 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_rea... |
| CVE-2025-39889 | MEDIUM | 5.5 | 0.1% | Sep 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on inco... |
| CVE-2025-58457 | MEDIUM | 4.3 | 0.3% | Sep 24, 2025 | Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu... |
| CVE-2025-9031 | MEDIUM | 4.3 | 0.2% | Sep 24, 2025 | Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Doma... |
| CVE-2025-41716 | MEDIUM | 5.3 | 0.4% | Sep 24, 2025 | The web application allows an unauthenticated remote attacker to learn information about existing user accounts with the... |
| CVE-2025-41715 | CRITICAL | 9.8 | 0.5% | Sep 24, 2025 | The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to g... |
| CVE-2025-48459 | MEDIUM | 5.3 | 0.5% | Sep 24, 2025 | Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0... |
| CVE-2025-48392 | HIGH | 7.5 | 0.6% | Sep 24, 2025 | A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now