2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53538 | HIGH | 7.5 | 0.4% | Jul 22, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-48733 | HIGH | 8.7 | 0.4% | Jul 22, 2025 | DuraComm SPM-500 DP-10iN-100-MU lacks access controls for a function that should require user authentication. This cou... |
| CVE-2025-41425 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | DuraComm SPM-500 DP-10iN-100-MU is vulnerable to a cross-site scripting attack. This could allow an attacker to preven... |
| CVE-2025-8044 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-8043 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir... |
| CVE-2025-8040 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these b... |
| CVE-2025-8039 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability ... |
| CVE-2025-8038 | CRITICAL | 9.8 | 0.2% | Jul 22, 2025 | Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox ... |
| CVE-2025-8037 | CRITICAL | 9.1 | 0.2% | Jul 22, 2025 | Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o... |
| CVE-2025-8036 | HIGH | 8.1 | 0.4% | Jul 22, 2025 | Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebindin... |
| CVE-2025-8035 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Fire... |
| CVE-2025-8034 | HIGH | 8.8 | 0.4% | Jul 22, 2025 | Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder... |
| CVE-2025-8033 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr... |
| CVE-2025-8032 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fix... |
| CVE-2025-8031 | CRITICAL | 9.8 | 0.4% | Jul 22, 2025 | The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti... |
| CVE-2025-8030 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected ... |
| CVE-2025-8029 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox ... |
| CVE-2025-8028 | CRITICAL | 9.8 | 0.5% | Jul 22, 2025 | On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction... |
| CVE-2025-8027 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, howeve... |
| CVE-2025-7724 | HIGH | 8.7 | 0.9% | Jul 22, 2025 | An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue... |
| CVE-2025-7723 | HIGH | 8.5 | 0.8% | Jul 22, 2025 | A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2... |
| CVE-2025-51462 | MEDIUM | 6.1 | 0.3% | Jul 22, 2025 | Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attack... |
| CVE-2025-51475 | MEDIUM | 5 | 0.8% | Jul 22, 2025 | Arbitrary File Overwrite (AFO) in superagi.controllers.resources.upload in TransformerOptimus SuperAGI 0.0.14 allows rem... |
| CVE-2025-51472 | MEDIUM | 6.5 | 0.4% | Jul 22, 2025 | Code Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execu... |
| CVE-2025-51458 | MEDIUM | 6.5 | 0.3% | Jul 22, 2025 | SQL Injection in editor_sql_run and query_ex in eosphoros-ai DB-GPT 0.7.0 allows remote attackers to execute arbitrary S... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now