2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-23323 | HIGH | 7.5 | 0.5% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overfl... |
| CVE-2025-23322 | HIGH | 7.5 | 0.5% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a doub... |
| CVE-2025-23321 | HIGH | 7.5 | 0.4% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause a divide by zero ... |
| CVE-2025-23320 | HIGH | 7.5 | 0.9% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c... |
| CVE-2025-23319 | CRITICAL | 9.8 | 1.5% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c... |
| CVE-2025-23318 | CRITICAL | 9.8 | 0.6% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c... |
| CVE-2025-23317 | CRITICAL | 9.8 | 1.8% | Aug 6, 2025 | NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shel... |
| CVE-2025-23311 | CRITICAL | 9.8 | 2.5% | Aug 6, 2025 | NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a stack overflow through specially... |
| CVE-2025-23310 | CRITICAL | 9.8 | 1.8% | Aug 6, 2025 | NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer... |
| CVE-2025-5197 | MEDIUM | 5.3 | 0.4% | Aug 6, 2025 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifical... |
| CVE-2025-46391 | MEDIUM | 6.5 | 0.2% | Aug 6, 2025 | CWE-284: Improper Access Control |
| CVE-2025-46390 | HIGH | 7.5 | 0.3% | Aug 6, 2025 | CWE-204: Observable Response Discrepancy |
| CVE-2025-46389 | MEDIUM | 6.5 | 0.2% | Aug 6, 2025 | CWE-620: Unverified Password Change |
| CVE-2025-46388 | MEDIUM | 4.3 | 0.2% | Aug 6, 2025 | CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
| CVE-2025-46387 | HIGH | 8.8 | 0.3% | Aug 6, 2025 | CWE-639 Authorization Bypass Through User-Controlled Key |
| CVE-2025-46386 | HIGH | 8.8 | 0.3% | Aug 6, 2025 | CWE-639 Authorization Bypass Through User-Controlled Key |
| CVE-2025-8620 | MEDIUM | 5.3 | 0.5% | Aug 6, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ... |
| CVE-2025-7771 | HIGH | 8.7 | 9.0% | Aug 6, 2025 | ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physic... |
| CVE-2025-6013 | HIGH | 8.1 | 0.5% | Aug 6, 2025 | Vault and Vault Enterprise’s (“Vault”) ldap auth method may not have correctly enforced MFA if username_as_alias was set... |
| CVE-2025-22470 | CRITICAL | 9.8 | 0.7% | Aug 6, 2025 | CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions prior to 1.15.5-r1 allow crafted dangerous file... |
| CVE-2025-22469 | HIGH | 7.3 | 1.1% | Aug 6, 2025 | OS command injection vulnerability exists in CL4/6NX Plus and CL4/6NX-J Plus (Japan model) with the firmware versions pr... |
| CVE-2025-8556 | LOW | 3.7 | 0.5% | Aug 6, 2025 | A flaw was found in CIRCL's implementation of the FourQ elliptic curve. This vulnerability allows an attacker to comprom... |
| CVE-2025-7202 | MEDIUM | 5.1 | 0.2% | Aug 6, 2025 | A Cross-Site Request Forgery (CSRF) in Elgato's Key Lights and related light products allows an attacker to host a malic... |
| CVE-2025-7954 | HIGH | 8.1 | 0.4% | Aug 6, 2025 | A race condition vulnerability has been identified in Shopware's voucher system of Shopware v6.6.10.4 that allows attack... |
| CVE-2025-47324 | HIGH | 7.5 | 0.2% | Aug 6, 2025 | Information disclosure while accessing and modifying the PIB file of a remote device via powerline. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now