2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-8036HIGH8.1Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebindin...
CVE-2025-8035HIGH8.8Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Fire...
CVE-2025-8034HIGH8.8Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder...
CVE-2025-8032HIGH8.1XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fix...
CVE-2025-8030HIGH8.1Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected ...
CVE-2025-8029HIGH8.1Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox ...
CVE-2025-7724HIGH8.7An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue...
CVE-2025-7723HIGH8.5A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2...
CVE-2025-31512HIGH7.3An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover ...
CVE-2025-31511HIGH7.3An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user I...
CVE-2025-51464HIGH8.8Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims bro...
CVE-2025-6741HIGH7.7Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthor...
CVE-2025-51482HIGH8.8Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem...
CVE-2025-8019HIGH8.8A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected ...
CVE-2025-5042HIGH7.8A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal...
CVE-2025-51480HIGH8.8Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit...
CVE-2025-51463HIGH7Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's fi...
CVE-2025-48498HIGH7.5A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when pr...
CVE-2025-46354HIGH7.5A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomber...
CVE-2025-36520HIGH7.5A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg...
CVE-2025-36512HIGH7.5A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction he...
CVE-2025-35966HIGH7.5A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2...
CVE-2025-8018HIGH8.8A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected b...
CVE-2025-51865HIGH8.8Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object ...
CVE-2025-8017HIGH8.8A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSet...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now