2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-33251HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...
CVE-2025-33250HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit...
CVE-2025-33249HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input ...
CVE-2025-33246HIGH7.8NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause ...
CVE-2025-33245HIGH8.8NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful expl...
CVE-2025-33243HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed enviro...
CVE-2025-33241HIGH7.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciou...
CVE-2025-33240HIGH7.8NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code i...
CVE-2025-33239HIGH7.8NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code inj...
CVE-2025-33236HIGH7.8NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A...
CVE-2025-14340HIGH7.3Cross-site scripting in REST Management Interface in Payara Server <4.1.2.191.54, <5.83.0, <6.34.0, <7.2026.1 allows an ...
CVE-2025-8781MEDIUM4.9The Bookster – WordPress Appointment Booking Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘raw’ pa...
CVE-2025-7630MEDIUM5.3Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication ...
CVE-2025-14799MEDIUM6.5The Brevo - Email, SMS, Web Push, Chat, and more. plugin for WordPress is vulnerable to authorization bypass due to type...
CVE-2025-14444MEDIUM5.3The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-13727MEDIUM4.4The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2025-11185MEDIUM6.4The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi...
CVE-2025-12356MEDIUM4.3The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to unauthorized modification of data due t...
CVE-2025-12122MEDIUM6.4The Popup Box – Easily Create WordPress Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
CVE-2025-11737MEDIUM6.4The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_sns...
CVE-2025-6460MEDIUM6.4The Display During Conditional Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mess...
CVE-2025-13959MEDIUM6.4The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode ...
CVE-2025-12075MEDIUM4.3The Order Splitter for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca...
CVE-2025-12074MEDIUM5.3The Context Blog theme for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.5 v...
CVE-2025-12071MEDIUM4.3The Frontend User Notes plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now