Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2025-23304

CVE-2025-23304_CVE-2025-23304

NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by load...

NVIDIA NVIDIA NeMo Framework All versions prior to 2.3.2 CVE
HIGH 7.8 CVE-2025-23303

CVE-2025-23303_CVE-2025-23303

NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execut...

NVIDIA NVIDIA NeMo Framework All versions prior to 2.3.2 CVE
HIGH 7.8 CVE-2025-23295

CVE-2025-23295_CVE-2025-23295

NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue by providing a ma...

NVIDIA NVIDIA Apex All versions before release 25.07 CVE
HIGH 7.8 CVE-2025-23298

CVE-2025-23298_CVE-2025-23298

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection is...

NVIDIA NVIDIA Merlin Transformers4Rec All versions that do not include code commit b7eaea5 CVE
HIGH 7.8 CVE-2025-23296

CVE-2025-23296_CVE-2025-23296

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue. A success...

NVIDIA NVIDIA Isaac-GR00T N1 All versions that do not include code commit 9ca97e1 CVE
HIGH 7.8 CVE-2025-23306

CVE-2025-23306_CVE-2025-23306

NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an attacker could cause a code...

NVIDIA Megatron-LM All versions prior to 0.12.2 CVE
HIGH 7.8 CVE-2025-23305

CVE-2025-23305_CVE-2025-23305

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a code injection issue. A succe...

NVIDIA Megatron-LM All versions prior to 0.12.2 CVE
HIGH 8.1 CVE-2025-54701

WordPress Unicamp Theme <= 2.6.3 - Local File Inclusion Vulnerability_CVE-2025-54701

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp allows P...

ThemeMove Unicamp n/a CVE
HIGH 8.1 CVE-2025-54700

WordPress Makeaholic Theme <= 1.8.4 - Local File Inclusion Vulnerability_CVE-2025-54700

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic allow...

ThemeMove Makeaholic n/a CVE
HIGH 7.2 CVE-2025-54697

WordPress Kadence WooCommerce Email Designer Plugin <= 1.5.16 - Privilege Escalation Vulnerability_CVE-2025-54697

Incorrect Privilege Assignment vulnerability in Ben Ritner - Kadence WP Kadence WooCommerce Email Designer allows Privilege Escalation. This issue ...

Ben Ritner - Kadence WP Kadence WooCommerce Email Designer n/a CVE