2025 CVE Vulnerabilities

45,343 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8039HIGH8.1In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability ...
CVE-2025-8036HIGH8.1Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebindin...
CVE-2025-8035HIGH8.8Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Fire...
CVE-2025-8034HIGH8.8Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder...
CVE-2025-8032HIGH8.1XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fix...
CVE-2025-8030HIGH8.1Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected ...
CVE-2025-8029HIGH8.1Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox ...
CVE-2025-7724HIGH8.7An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue...
CVE-2025-7723HIGH8.5A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2...
CVE-2025-31512HIGH7.3An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover ...
CVE-2025-31511HIGH7.3An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user I...
CVE-2025-51464HIGH8.8Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims bro...
CVE-2025-6741HIGH7.7Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthor...
CVE-2025-51482HIGH8.8Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem...
CVE-2025-8019HIGH8.8A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected ...
CVE-2025-5042HIGH7.8A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal...
CVE-2025-51480HIGH8.8Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit...
CVE-2025-51463HIGH7Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's fi...
CVE-2025-48498HIGH7.5A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when pr...
CVE-2025-46354HIGH7.5A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomber...
CVE-2025-36520HIGH7.5A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg...
CVE-2025-36512HIGH7.5A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction he...
CVE-2025-35966HIGH7.5A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2...
CVE-2025-8018HIGH8.8A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected b...
CVE-2025-51865HIGH8.8Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now