2025 CVE Vulnerabilities
45,221 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9178 | HIGH | 7.7 | 0.3% | Oct 14, 2025 | A denial-of-service security issue exists in the affected product and version. The security issue is caused through CIP ... |
| CVE-2025-9177 | HIGH | 7.7 | 0.3% | Oct 14, 2025 | A denial-of-service security issue exists in the affected product and version. The security issue stems from a high numb... |
| CVE-2025-9124 | HIGH | 8.7 | 0.4% | Oct 14, 2025 | A denial-of-service security issue in the affected product. The security issue stems from a fault occurring when a craft... |
| CVE-2025-9068 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair function... |
| CVE-2025-9067 | HIGH | 7.8 | 0.2% | Oct 14, 2025 | A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers wi... |
| CVE-2025-9066 | HIGH | 8.7 | 0.4% | Oct 14, 2025 | A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certai... |
| CVE-2025-9064 | CRITICAL | 9.1 | 0.6% | Oct 14, 2025 | A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on th... |
| CVE-2025-9063 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exp... |
| CVE-2025-7330 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missi... |
| CVE-2025-7329 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious use... |
| CVE-2025-7328 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing aut... |
| CVE-2025-11721 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presu... |
| CVE-2025-11720 | HIGH | 8.1 | 0.2% | Oct 14, 2025 | The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full... |
| CVE-2025-11719 | CRITICAL | 9.8 | 0.3% | Oct 14, 2025 | Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caus... |
| CVE-2025-11718 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool th... |
| CVE-2025-11717 | CRITICAL | 9.1 | 0.2% | Oct 14, 2025 | When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a passwo... |
| CVE-2025-11716 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | Links in a sandboxed iframe could open an external app on Android without the required "allow-" permission. This vulnera... |
| CVE-2025-11715 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | Memory safety bugs present in Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird 143. Some of these b... |
| CVE-2025-11714 | HIGH | 8.8 | 0.3% | Oct 14, 2025 | Memory safety bugs present in Firefox ESR 115.28, Firefox ESR 140.3, Thunderbird ESR 140.3, Firefox 143 and Thunderbird ... |
| CVE-2025-11713 | HIGH | 8.1 | 0.3% | Oct 14, 2025 | Insufficient escaping in the “Copy as cURL” feature could have been used to trick a user into executing unexpected code ... |
| CVE-2025-11712 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | A malicious page could have used the type attribute of an OBJECT tag to override the default browser behavior when encou... |
| CVE-2025-11711 | MEDIUM | 6.5 | 0.2% | Oct 14, 2025 | There was a way to change the value of JavaScript Object properties that were supposed to be non-writeable. This vulnera... |
| CVE-2025-11710 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks... |
| CVE-2025-11709 | CRITICAL | 9.8 | 0.4% | Oct 14, 2025 | A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipula... |
| CVE-2025-11708 | CRITICAL | 9.8 | 0.5% | Oct 14, 2025 | Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now