2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20215MEDIUM5.4A vulnerability in the meeting-join functionality of Cisco Webex Meetings could have allowed an unauthenticated, network...
CVE-2025-53786HIGH8On April 18th 2025, Microsoft announced Exchange Server Security Changes for Hybrid Deployments and accompanying non-sec...
CVE-2025-51532HIGH7.5Incorrect access control in Sage DPW 2024_12_004 and earlier allows unauthorized attackers to access the built-in Databa...
CVE-2025-51531MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability in Sage DPW 2024_12_004 and earlier allows attackers to execute arb...
CVE-2025-48394MEDIUM4.7An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the...
CVE-2025-48393MEDIUM5.7The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potential...
CVE-2025-51308MEDIUM5.3In Gatling Enterprise versions below 1.25.0, a low-privileged user that does not hold the role "admin" could perform a R...
CVE-2025-51306MEDIUM6.5In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the ap...
CVE-2025-51040HIGH7.5Electrolink FM/DAB/TV Transmitter Web Management System Unauthorized access vulnerability via the /FrameSetCore.html end...
CVE-2025-50286HIGH8.1A Remote Code Execution (RCE) vulnerability in Grav CMS v1.7.48 allows an authenticated admin to upload a malicious plug...
CVE-2025-50234MEDIUM6.5MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where ...
CVE-2025-50233MEDIUM6.5A vulnerability in QCMS version 6.0.5 allows authenticated users to read arbitrary files from the server due to insuffic...
CVE-2025-36020HIGH7.5IBM Guardium Data Protection could allow a remote attacker to obtain sensitive information due to cleartext transmission...
CVE-2025-2028MEDIUM5.3Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying coun...
CVE-2025-8616MEDIUM6.1A weakness identified in OpenText Advanced Authentication where a Malicious browser plugin can record and replay the use...
CVE-2025-3354CRITICAL9.8IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i...
CVE-2025-3320CRITICAL9.8IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by i...
CVE-2025-23335HIGH7.5NVIDIA Triton Inference Server for Windows and Linux and the Tensor RT backend contain a vulnerability where an attacker...
CVE-2025-23334HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23333HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23331HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a memory allocati...
CVE-2025-23327CRITICAL9.1NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o...
CVE-2025-23326HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer o...
CVE-2025-23325HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled...
CVE-2025-23324HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now