2025 CVE Vulnerabilities

45,230 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23348HIGH7.8NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created b...
CVE-2025-23346LOW3.3NVIDIA CUDA Toolkit contains a vulnerability in cuobjdump, where an unprivileged user can cause a NULL pointer dereferen...
CVE-2025-23340LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b...
CVE-2025-23339HIGH7.8NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based bu...
CVE-2025-23338MEDIUM5.5NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where a user may cause an out-of-bounds write...
CVE-2025-23308HIGH7.8NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buff...
CVE-2025-23275HIGH7.1NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GP...
CVE-2025-23274MEDIUM4.5NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a mali...
CVE-2025-23273MEDIUM4.7NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a di...
CVE-2025-23272MEDIUM5.7NVIDIA nvJPEG library contains a vulnerability where an attacker can cause an out-of-bounds read by means of a specially...
CVE-2025-23271LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b...
CVE-2025-23255LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the cuobjdump binary where a user may cause an out-of-...
CVE-2025-23248LOW3.3NVIDIA CUDA Toolkit for all platforms contains a vulnerability in the nvdisasm binary where a user may cause an out-of-b...
CVE-2025-9353MEDIUM6.4The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all vers...
CVE-2025-60020MEDIUM6.4nncp before 8.12.0 allows path traversal (for reading or writing) during freqing and file saving via a crafted path in p...
CVE-2025-10906HIGH8.4A flaw has been found in Magnetism Studios Endurance up to 3.3.0 on macOS. This affects the function loadModuleNamed:Wit...
CVE-2025-9054CRITICAL9.8The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi...
CVE-2025-39890MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix memory leak in ath12k_service_rea...
CVE-2025-39889MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: Check encryption key size on inco...
CVE-2025-58457MEDIUM4.3Improper permission check in ZooKeeper AdminServer lets authorized clients to run snapshot and restore command with insu...
CVE-2025-9031MEDIUM4.3Observable Timing Discrepancy vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive Web allows Cross-Doma...
CVE-2025-41716MEDIUM5.3The web application allows an unauthenticated remote attacker to learn information about existing user accounts with the...
CVE-2025-41715CRITICAL9.8The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to g...
CVE-2025-48459MEDIUM5.3Deserialization of Untrusted Data vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 2.0...
CVE-2025-48392HIGH7.5A vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.3.3 through 1.3.4, from 2.0.1-beta through 2.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now