2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33251 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit... |
| CVE-2025-33250 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit... |
| CVE-2025-33249 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input ... |
| CVE-2025-33246 | HIGH | 7.8 | 0.9% | Feb 18, 2026 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause ... |
| CVE-2025-33245 | HIGH | 8.8 | 0.5% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl... |
| CVE-2025-33243 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed enviro... |
| CVE-2025-33241 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciou... |
| CVE-2025-33240 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code i... |
| CVE-2025-33239 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code inj... |
| CVE-2025-33236 | HIGH | 7.8 | 0.2% | Feb 18, 2026 | NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A... |
| CVE-2025-14340 | HIGH | 7.3 | 1.0% | Feb 18, 2026 | Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an ... |
| CVE-2025-8781 | MEDIUM | 4.9 | 0.3% | Feb 18, 2026 | The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ pa... |
| CVE-2025-7630 | MEDIUM | 5.3 | 0.2% | Feb 18, 2026 | Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication ... |
| CVE-2025-14799 | MEDIUM | 6.5 | 0.5% | Feb 18, 2026 | The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type... |
| CVE-2025-14444 | MEDIUM | 5.3 | 0.2% | Feb 18, 2026 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
| CVE-2025-13727 | MEDIUM | 4.4 | 0.3% | Feb 18, 2026 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-11185 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2025-12356 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due t... |
| CVE-2025-12122 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-11737 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns... |
| CVE-2025-6460 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mess... |
| CVE-2025-13959 | MEDIUM | 6.4 | 0.2% | Feb 18, 2026 | The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode ... |
| CVE-2025-12075 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2025-12074 | MEDIUM | 5.3 | 0.3% | Feb 18, 2026 | The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 v... |
| CVE-2025-12071 | MEDIUM | 4.3 | 0.2% | Feb 18, 2026 | The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now