2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8036 | HIGH | 8.1 | 0.4% | Jul 22, 2025 | Thunderbird cached CORS preflight responses across IP address changes. This allowed circumventing CORS with DNS rebindin... |
| CVE-2025-8035 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Fire... |
| CVE-2025-8034 | HIGH | 8.8 | 0.4% | Jul 22, 2025 | Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunder... |
| CVE-2025-8032 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fix... |
| CVE-2025-8030 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected ... |
| CVE-2025-8029 | HIGH | 8.1 | 0.3% | Jul 22, 2025 | Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox ... |
| CVE-2025-7724 | HIGH | 8.7 | 0.9% | Jul 22, 2025 | An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue... |
| CVE-2025-7723 | HIGH | 8.5 | 0.8% | Jul 22, 2025 | A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2... |
| CVE-2025-31512 | HIGH | 7.3 | 0.4% | Jul 22, 2025 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover ... |
| CVE-2025-31511 | HIGH | 7.3 | 0.4% | Jul 22, 2025 | An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user I... |
| CVE-2025-51464 | HIGH | 8.8 | 0.6% | Jul 22, 2025 | Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims bro... |
| CVE-2025-6741 | HIGH | 7.7 | 0.4% | Jul 22, 2025 | Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthor... |
| CVE-2025-51482 | HIGH | 8.8 | 1.9% | Jul 22, 2025 | Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows rem... |
| CVE-2025-8019 | HIGH | 8.8 | 0.8% | Jul 22, 2025 | A vulnerability was found in Shenzhen Libituo Technology LBT-T300-T310 2.2.3.6. It has been rated as critical. Affected ... |
| CVE-2025-5042 | HIGH | 7.8 | 0.2% | Jul 22, 2025 | A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A mal... |
| CVE-2025-51480 | HIGH | 8.8 | 0.6% | Jul 22, 2025 | Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrit... |
| CVE-2025-51463 | HIGH | 7 | 0.5% | Jul 22, 2025 | Path Traversal in restore_run_backup() in AIM 3.28.0 allows remote attackers to write arbitrary files to the server's fi... |
| CVE-2025-48498 | HIGH | 7.5 | 0.6% | Jul 22, 2025 | A null pointer dereference vulnerability exists in the Distributed Transaction component of Bloomberg Comdb2 8.1 when pr... |
| CVE-2025-46354 | HIGH | 7.5 | 0.9% | Jul 22, 2025 | A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomber... |
| CVE-2025-36520 | HIGH | 7.5 | 0.9% | Jul 22, 2025 | A null pointer dereference vulnerability exists in the net_connectmsg Protocol Buffer Message functionality of Bloomberg... |
| CVE-2025-36512 | HIGH | 7.5 | 0.5% | Jul 22, 2025 | A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction he... |
| CVE-2025-35966 | HIGH | 7.5 | 0.6% | Jul 22, 2025 | A null pointer dereference vulnerability exists in the CDB2SQLQUERY protocol buffer message handling of Bloomberg Comdb2... |
| CVE-2025-8018 | HIGH | 8.8 | 0.4% | Jul 22, 2025 | A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected b... |
| CVE-2025-51865 | HIGH | 8.8 | 0.4% | Jul 22, 2025 | Ai2 playground web service (playground.allenai.org) LLM chat through 2025-06-03 is vulnerable to Insecure Direct Object ... |
| CVE-2025-8017 | HIGH | 8.8 | 8.3% | Jul 22, 2025 | A vulnerability was found in Tenda AC7 15.03.06.44. It has been classified as critical. Affected is the function formSet... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now