2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53538HIGH7.5Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric...
CVE-2025-48733HIGH8.7DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This cou...
CVE-2025-41425HIGH8.1DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to preven...
CVE-2025-8044CRITICAL9.8Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a...
CVE-2025-8043CRITICAL9.8Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir...
CVE-2025-8040HIGH8.8Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these b...
CVE-2025-8039HIGH8.1In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability ...
CVE-2025-8038CRITICAL9.8Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox ...
CVE-2025-8037CRITICAL9.1Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o...
CVE-2025-8036HIGH8.1Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebindin...
CVE-2025-8035HIGH8.8Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Fire...
CVE-2025-8034HIGH8.8Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder...
CVE-2025-8033MEDIUM6.5The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr...
CVE-2025-8032HIGH8.1XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fix...
CVE-2025-8031CRITICAL9.8The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti...
CVE-2025-8030HIGH8.1Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected ...
CVE-2025-8029HIGH8.1Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox ...
CVE-2025-8028CRITICAL9.8On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction...
CVE-2025-8027MEDIUM6.5On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, howeve...
CVE-2025-7724HIGH8.7An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue...
CVE-2025-7723HIGH8.5A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2...
CVE-2025-51462MEDIUM6.1Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attack...
CVE-2025-51475MEDIUM5Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows rem...
CVE-2025-51472MEDIUM6.5Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execu...
CVE-2025-51458MEDIUM6.5SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary S...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now