2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10537HIGH8.8Memory safety bugs present in Firefox ESR 140.2, Thunderbird ESR 140.2, Firefox 142 and Thunderbird 142. Some of these b...
CVE-2025-10536MEDIUM6.2Information disclosure in the Networking: Cache component. This vulnerability was fixed in Firefox 143, Firefox ESR 140....
CVE-2025-10535HIGH7.5Information disclosure, mitigation bypass in the Privacy component in Firefox for Android. This vulnerability was fixed ...
CVE-2025-10534HIGH8.1Spoofing issue in the Site Permissions component. This vulnerability was fixed in Firefox 143 and Thunderbird 143.
CVE-2025-10533HIGH8.8Integer overflow in the SVG component. This vulnerability was fixed in Firefox 143, Firefox ESR 115.28, Firefox ESR 140....
CVE-2025-10532MEDIUM6.5Incorrect boundary conditions in the JavaScript: GC component. This vulnerability was fixed in Firefox 143, Firefox ESR ...
CVE-2025-10531MEDIUM5.4Mitigation bypass in the Web Compatibility: Tooling component. This vulnerability was fixed in Firefox 143 and Thunderbi...
CVE-2025-10530MEDIUM6.5Spoofing issue in the WebAuthn component in Firefox for Android. This vulnerability was fixed in Firefox 143 and Thunder...
CVE-2025-10529MEDIUM6.5Same-origin policy bypass in the Layout component. This vulnerability was fixed in Firefox 143, Firefox ESR 140.3, Thund...
CVE-2025-10528HIGH7.3Sandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D component. This vulnerability was fi...
CVE-2025-10527HIGH7.1Sandbox escape due to use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox 143, F...
CVE-2025-10290MEDIUM6.5Opening links via the contextual menu in Focus iOS for certain URL schemes would fail to load but would not refresh the ...
CVE-2025-8446MEDIUM4.3The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized limited plugin install due to a missing capab...
CVE-2025-7744CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dolusoft Omaspot a...
CVE-2025-7743CRITICAL9.6Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalat...
CVE-2025-6575MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dolusoft Om...
CVE-2025-56706HIGH8Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter ...
CVE-2025-56697MEDIUM6.1A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the /users/adminpanel/admin/home.php?page=feedbacks ...
CVE-2025-41249HIGH7.5The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarc...
CVE-2025-41248HIGH7.5The Spring Security annotation detection mechanism may not correctly resolve annotations on methods within type hierarch...
CVE-2025-26711MEDIUM5.7There is an unauthorized access vulnerability in ZTE T5400. Due to improper permission control of the Web module interfa...
CVE-2025-26710LOW3.5There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control me...
CVE-2025-10016HIGH8.8The Sparkle framework includes a helper tool Autoupdate. Due to lack of authentication of connecting clients a local unp...
CVE-2025-10015MEDIUM4.8The Sparkle framework includes an XPC service Downloader.xpc, by default this service is private to the application its ...
CVE-2025-4688CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in BGS Interactive SI...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now