2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40615MEDIUM6.1Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScrip...
CVE-2025-32354HIGH8.8In Zimbra Collaboration (ZCS) 9.0 through 10.1, a Cross-Site Request Forgery (CSRF) vulnerability exists in the GraphQL ...
CVE-2025-25962CRITICAL9.8An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows a remote attacker to escalate privileges via the ...
CVE-2025-25403CRITICAL9.8Slims (Senayan Library Management Systems) 9 Bulian V9.6.1 is vulnerable to SQL Injection in admin/modules/master_file/c...
CVE-2025-23179MEDIUM5.5CWE-798: Use of Hard-coded Credentials
CVE-2025-23178HIGH7.6CWE-923: Improper Restriction of Communication Channel to Intended Endpoints
CVE-2025-23177HIGH7.6CWE-427: Uncontrolled Search Path Element
CVE-2025-1551MEDIUM6.1IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, and 9.0.0.1 is vulnerable to cross-site scripting. This v...
CVE-2025-4067MEDIUM6.9A vulnerability classified as critical has been found in ScriptAndTools Online-Travling-System 1.0. Affected is an unkno...
CVE-2025-4066CRITICAL9.8A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been rated as critical. This issue affect...
CVE-2025-4065HIGH7.5A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been declared as critical. This vulnerabi...
CVE-2025-4093HIGH8.1Memory safety bug present in Firefox ESR 128.9, and Thunderbird 128.9. This bug showed evidence of memory corruption and...
CVE-2025-4092MEDIUM6.5Memory safety bugs present in Firefox 137 and Thunderbird 137. Some of these bugs showed evidence of memory corruption a...
CVE-2025-4091HIGH8.1Memory safety bugs present in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9. Some of these bugs...
CVE-2025-4090MEDIUM5.3A vulnerability existed in Thunderbird for Android where potentially sensitive library locations were logged via Logcat....
CVE-2025-4089MEDIUM5.1Due to insufficient escaping of special characters in the "copy as cURL" feature, an attacker could trick a user into us...
CVE-2025-4088MEDIUM6.5A security vulnerability in Thunderbird allowed malicious sites to use redirects to send credentialed requests to arbitr...
CVE-2025-4087MEDIUM4.8A vulnerability was identified in Thunderbird where XPath parsing could trigger undefined behavior due to missing null c...
CVE-2025-4086MEDIUM6.5A specially crafted filename containing a large number of encoded newline characters could obscure the file's extension ...
CVE-2025-4085HIGH7.1An attacker with control over a content process could potentially leverage the privileged UITour actor to leak sensitive...
CVE-2025-4084MEDIUM5.7Due to insufficient escaping of the special characters in the "copy as cURL" feature, an attacker could trick a user int...
CVE-2025-4083CRITICAL9.1A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow c...
CVE-2025-4082MEDIUM5.9Modification of specific WebGL shader attributes could trigger an out-of-bounds read, which, when chained with other vul...
CVE-2025-4064MEDIUM6.9A vulnerability was found in ScriptAndTools Online-Travling-System 1.0. It has been classified as critical. This affects...
CVE-2025-4063HIGH7.8A vulnerability was found in code-projects Student Information Management System 1.0 and classified as critical. Affecte...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now