2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-23323HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl...
CVE-2025-23322HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a doub...
CVE-2025-23321HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero ...
CVE-2025-23320HIGH7.5NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23319CRITICAL9.8NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23318CRITICAL9.8NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23317CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shel...
CVE-2025-23311CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially...
CVE-2025-23310CRITICAL9.8NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer...
CVE-2025-5197MEDIUM5.3A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifical...
CVE-2025-46391MEDIUM6.5CWE-284: Improper Access Control
CVE-2025-46390HIGH7.5CWE-204: Observable Response Discrepancy
CVE-2025-46389MEDIUM6.5CWE-620: Unverified Password Change
CVE-2025-46388MEDIUM4.3CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-46387HIGH8.8CWE-639 Authorization Bypass Through User-Controlled Key
CVE-2025-46386HIGH8.8CWE-639 Authorization Bypass Through User-Controlled Key
CVE-2025-8620MEDIUM5.3The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ...
CVE-2025-7771HIGH8.7ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physic...
CVE-2025-6013HIGH8.1Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set...
CVE-2025-22470CRITICAL9.8CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous file...
CVE-2025-22469HIGH7.3OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions pr...
CVE-2025-8556LOW3.7A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to comprom...
CVE-2025-7202MEDIUM5.1A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malic...
CVE-2025-7954HIGH8.1A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attack...
CVE-2025-47324HIGH7.5Information disclosure while accessing and modifying the PIB file of a remote device via powerline.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now