2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10537 | HIGH | 8.8 | 0.3% | Sep 16, 2025 | Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these b... |
| CVE-2025-10536 | MEDIUM | 6.2 | 0.2% | Sep 16, 2025 | Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.... |
| CVE-2025-10535 | HIGH | 7.5 | 0.3% | Sep 16, 2025 | Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed ... |
| CVE-2025-10534 | HIGH | 8.1 | 0.3% | Sep 16, 2025 | Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143. |
| CVE-2025-10533 | HIGH | 8.8 | 0.7% | Sep 16, 2025 | Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140.... |
| CVE-2025-10532 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR ... |
| CVE-2025-10531 | MEDIUM | 5.4 | 0.3% | Sep 16, 2025 | Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbi... |
| CVE-2025-10530 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunder... |
| CVE-2025-10529 | MEDIUM | 6.5 | 0.3% | Sep 16, 2025 | Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thund... |
| CVE-2025-10528 | HIGH | 7.3 | 0.3% | Sep 16, 2025 | Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fi... |
| CVE-2025-10527 | HIGH | 7.1 | 0.3% | Sep 16, 2025 | Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, F... |
| CVE-2025-10290 | MEDIUM | 6.5 | 0.2% | Sep 16, 2025 | Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the ... |
| CVE-2025-8446 | MEDIUM | 4.3 | 0.2% | Sep 16, 2025 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capab... |
| CVE-2025-7744 | CRITICAL | 9.8 | 0.3% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dolusoft Omaspot a... |
| CVE-2025-7743 | CRITICAL | 9.6 | 0.1% | Sep 16, 2025 | Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalat... |
| CVE-2025-6575 | MEDIUM | 6.1 | 0.2% | Sep 16, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dolusoft Om... |
| CVE-2025-56706 | HIGH | 8 | 1.8% | Sep 16, 2025 | Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter ... |
| CVE-2025-56697 | MEDIUM | 6.1 | 0.3% | Sep 16, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks ... |
| CVE-2025-41249 | HIGH | 7.5 | 0.5% | Sep 16, 2025 | The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarc... |
| CVE-2025-41248 | HIGH | 7.5 | 0.4% | Sep 16, 2025 | The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarch... |
| CVE-2025-26711 | MEDIUM | 5.7 | 0.2% | Sep 16, 2025 | There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interfa... |
| CVE-2025-26710 | LOW | 3.5 | 0.2% | Sep 16, 2025 | There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control me... |
| CVE-2025-10016 | HIGH | 8.8 | 0.2% | Sep 16, 2025 | The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unp... |
| CVE-2025-10015 | MEDIUM | 4.8 | 0.1% | Sep 16, 2025 | The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its ... |
| CVE-2025-4688 | CRITICAL | 9.8 | 0.4% | Sep 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SI... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now