2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12942 | HIGH | 7.5 | 0.3% | Nov 11, 2025 | Improper Input Validation vulnerability in NETGEAR R6260 and NETGEAR R6850 allows unauthenticated attackers connected to... |
| CVE-2025-12940 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1... |
| CVE-2025-9408 | HIGH | 8.1 | 0.1% | Nov 11, 2025 | System call entry on Cortex M (and possibly R and A, but I think not) has a race which allows very practical privilege e... |
| CVE-2025-64773 | LOW | 3.7 | 0.2% | Nov 11, 2025 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit |
| CVE-2025-13027 | HIGH | 8.1 | 0.3% | Nov 11, 2025 | Memory safety bugs present in Firefox 144 and Thunderbird 144. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-13026 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in F... |
| CVE-2025-13025 | HIGH | 7.5 | 0.2% | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder... |
| CVE-2025-13024 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird ... |
| CVE-2025-13023 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in F... |
| CVE-2025-13022 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder... |
| CVE-2025-13021 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder... |
| CVE-2025-13020 | HIGH | 8.8 | 0.2% | Nov 11, 2025 | Use-after-free in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thu... |
| CVE-2025-13019 | HIGH | 8.1 | 0.2% | Nov 11, 2025 | Same-origin policy bypass in the DOM: Workers component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5,... |
| CVE-2025-13018 | HIGH | 8.1 | 0.2% | Nov 11, 2025 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Thunde... |
| CVE-2025-13017 | HIGH | 8.1 | 0.2% | Nov 11, 2025 | Same-origin policy bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 145, Firefox ESR ... |
| CVE-2025-13016 | HIGH | 7.5 | 0.4% | Nov 11, 2025 | Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 145, Fir... |
| CVE-2025-13015 | LOW | 3.4 | 0.2% | Nov 11, 2025 | Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30. |
| CVE-2025-13014 | HIGH | 8.8 | 0.2% | Nov 11, 2025 | Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR... |
| CVE-2025-13013 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Mitigation bypass in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Fir... |
| CVE-2025-13012 | HIGH | 7.5 | 0.2% | Nov 11, 2025 | Race condition in the Graphics component. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, Firefox ESR 11... |
| CVE-2025-10918 | HIGH | 7.1 | 0.2% | Nov 11, 2025 | Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticate... |
| CVE-2025-10905 | MEDIUM | 4.4 | 0.1% | Nov 11, 2025 | Collision in MiniFilter driver in Avast Software Avast Free Antivirus before 25.9 on Windows allows a local attacker w... |
| CVE-2025-11959 | HIGH | 8.1 | 0.2% | Nov 11, 2025 | Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor v... |
| CVE-2025-9227 | MEDIUM | 6.5 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine OpManager versions 128609 and below are vulnerable to Stored XSS Vulnerability in the SNMP trap pr... |
| CVE-2025-9223 | HIGH | 8.8 | 3.9% | Nov 11, 2025 | Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now