CVEs from 2025

8,954 normalized CVEs published or assigned in this year.

Total
8,954
critical
critical 1,368
high
high 2,067
medium
medium 2,068
low
low 204
% Critical
15.3%
% with KEV
2.0%
% with exploit
2.8%

Top products

  • i-educar 80
  • office_long_term_servicing_channel 35
  • office 34
  • best_salon_management_system 33
  • apartment_management_system 30
  • gcp 29
  • inventory_management_system 28
  • online_learning_management_system 21
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-38085 high 8.0 10mo ago Important: kernel security update
CVE-2025-38084 high 8.0 10mo ago Important: kernel security update
CVE-2025-4674 high 8.0 10mo ago Important: golang security update
CVE-2025-43216 high 8.0 10mo ago A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS…
CVE-2025-43240 high 8.0 10mo ago A logic issue was addressed with improved checks. This issue is fixed in Safari 18.6, macOS Sequoia 15.6. A download's origin may be incorrectly associated.
CVE-2025-43227 high 8.0 10mo ago This issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing malicio…
CVE-2025-43211 high 8.0 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processi…
CVE-2025-31278 high 8.0 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processi…
CVE-2025-43212 high 8.0 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-43265 high 8.0 10mo ago An out-of-bounds read was addressed with improved input validation. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing…
CVE-2025-31273 high 8.0 10mo ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously …
CVE-2025-23266 high 8.0 10mo ago Important: toolbox security update
CVE-2025-22020 high 8.0 10mo ago Important: kernel security update
CVE-2025-37890 high 8.0 10mo ago Important: kernel security update
CVE-2025-21928 high 8.0 10mo ago Important: kernel security update
CVE-2025-21962 high 8.0 10mo ago Important: kernel security update
CVE-2025-38087 high 8.0 10mo ago Important: kernel security update
CVE-2025-38052 high 8.0 10mo ago Important: kernel security update
CVE-2025-21929 high 8.0 10mo ago Important: kernel security update
CVE-2025-52999 high 8.0 10mo ago RHSA-2025:14126: pki-deps:10.6 security update (Important)
CVE-2025-5994 high 8.0 11mo ago RHSA-2025:11884: unbound security update (Important)
CVE-2025-27151 high 8.0 11mo ago Important: redis:7 security update
CVE-2025-8030 high 8.0 11mo ago Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox …
CVE-2025-8031 high 8.0 11mo ago The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vulnerability was fixed in Firefox 141, Firefox ESR 12…
CVE-2025-8034 high 8.0 11mo ago Memory safety bugs present in Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evid…
CVE-2025-8035 high 8.0 11mo ago Memory safety bugs present in Firefox ESR 128.12, Thunderbird ESR 128.12, Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corru…
CVE-2025-8027 high 8.0 11mo ago On 64-bit platforms IonMonkey-JIT only wrote 32 bits of the 64-bit return value space on the stack. Baseline-JIT, however, read the entire 64 bits. This vulnerability was fixed in Firefox 141, Firefo…
CVE-2025-8028 high 8.0 11mo ago On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and incorrect computation of the branch address. This vulne…
CVE-2025-8029 high 8.0 11mo ago Thunderbird executed `javascript:` URLs when used in `object` and `embed` tags. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13…
CVE-2025-8033 high 8.0 11mo ago The JavaScript engine did not handle closed generators correctly and it was possible to resume them leading to a nullptr deref. This vulnerability was fixed in Firefox 141, Firefox ESR 115.26, Firefo…
CVE-2025-8032 high 8.0 11mo ago XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thun…
CVE-2025-48367 high 8.0 11mo ago RHSA-2025:12006: redis:6 security update (Important)
CVE-2025-38425 high 8.0 11mo ago In the Linux kernel, the following vulnerability has been resolved: i2c: tegra: check msg length in SMBUS block read For SMBUS block read, do not continue to read if the message length passed from …
CVE-2025-27613 high 8.0 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-46835 high 8.0 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-27614 high 8.0 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-38089 high 8.0 11mo ago Important: kernel security update
CVE-2025-48385 high 8.0 11mo ago RHSA-2025:11534: git security update (Important)
CVE-2025-50106 high 8.0 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30761 high 8.0 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30754 high 8.0 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-30749 high 8.0 11mo ago Important: java-1.8.0-openjdk security update
CVE-2025-50059 high 8.0 11mo ago RHSA-2025:10873: java-21-openjdk security update (Important)
CVE-2025-30402 high 8.0 11mo ago ExecuTorch vulnerable to Heap-based Buffer Overflow attack
CVE-2025-6032 high 8.0 11mo ago RHSA-2025:10551: container-tools:rhel8 security update (Important)
CVE-2025-22004 high 8.0 11mo ago Important: kernel security update
CVE-2025-21759 high 8.0 11mo ago Important: kernel security update
CVE-2025-21887 high 8.0 11mo ago Important: kernel security update
CVE-2025-37799 high 8.0 11mo ago Important: kernel security update
CVE-2025-5986 high 8.0 11mo ago RHSA-2025:10246: thunderbird security update (Important)
CVE-2025-48379 high 8.0 11mo ago Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format…
CVE-2025-6429 high 8.0 11mo ago Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restric…
CVE-2025-6424 high 8.0 11mo ago A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140, Firefox ESR 115.25, Firefox ESR 128.12, Thunderbird 140, and Thunderbird 128.…
CVE-2025-4435 high 8.0 11mo ago Important: python3.9 security update
CVE-2025-6425 high 8.0 11mo ago An attacker who enumerated resources from the WebCompat extension could have obtained a persistent UUID that identified the browser, and persisted between containers and normal/private browsing mode,…
CVE-2025-4138 high 8.0 11mo ago Important: python3.9 security update
CVE-2025-6430 high 8.0 11mo ago When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `<embed>` or `<object>` tag, potentially making a we…
CVE-2025-4330 high 8.0 11mo ago Important: python3.9 security update
CVE-2025-4517 high 8.0 11mo ago Important: python3.9 security update
CVE-2025-49179 high 8.0 1y ago A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer overflow when computing request length, which allows a client to bypass length …
CVE-2025-49178 high 8.0 1y ago A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the server to skip processing another client's request, potentially leading to a denial…
CVE-2025-6019 high 8.0 1y ago RHSA-2025:9878: libblockdev security update (Important)
CVE-2025-49176 high 8.0 1y ago A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximum allowed size, potentially causing an integer overflow and bypassing the size …
CVE-2025-49180 high 8.0 1y ago A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. This issue leads to an integer overflow when computing the total size to allocat…
CVE-2025-49177 high 8.0 1y ago A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length, allowing a client to read unintended memory from previous requests.
CVE-2025-49175 high 8.0 1y ago A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the server assumes at least one is present, leading to an out-of-bounds read and potenti…
CVE-2025-40908 high 8.0 1y ago RHSA-2025:9329: perl-YAML-LibYAML security update (Important)
CVE-2025-6279 high 8.0 8.0 1y ago A vulnerability, which was classified as critical, has been found in Upsonic up to 0.55.6. This issue affects the function cloudpickle.loads of the file /tools/add_tool of the component Pickle Handle…
CVE-2025-48798 high 8.0 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-5473 high 8.0 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-4404 high 8.0 1y ago RHSA-2025:9188: idm:DL1 security update (Important)
CVE-2025-48797 high 8.0 1y ago RHSA-2025:9165: gimp:2.8 security update (Important)
CVE-2025-21969 high 8.0 1y ago Important: kernel security update
CVE-2025-21999 high 8.0 1y ago Important: kernel security update
CVE-2025-21963 high 8.0 1y ago Important: kernel security update
CVE-2025-21979 high 8.0 1y ago Important: kernel security update
CVE-2025-37750 high 8.0 1y ago Important: kernel security update
CVE-2025-22126 high 8.0 1y ago Important: kernel security update
CVE-2025-21961 high 8.0 1y ago Important: kernel security update
CVE-2025-48734 high 8.0 1y ago Apache Commons BeanUtils vulnerability
CVE-2025-30399 high 8.0 1y ago RHSA-2025:8815: .NET 9.0 security update (Important)
CVE-2025-47947 high 8.0 1y ago RHSA-2025:8844: mod_security security update (Important)
CVE-2025-40907 high 8.0 1y ago RHSA-2025:8696: perl-FCGI:0.78 security update (Important)
CVE-2025-37943 high 8.0 1y ago Important: kernel security update
CVE-2025-37785 high 8.0 1y ago Important: kernel security update
CVE-2025-22055 high 8.0 1y ago Important: kernel security update
CVE-2025-21997 high 8.0 1y ago Important: kernel security update
CVE-2025-21926 high 8.0 1y ago Important: kernel security update
CVE-2025-21920 high 8.0 1y ago Important: kernel security update
CVE-2025-23167 high 8.0 1y ago A flaw in Node.js 20's HTTP parser allows improper termination of HTTP/1 headers using `\r\n\rX` instead of the required `\r\n\r\n`. This inconsistency enables request smuggling, allowing attackers t…
CVE-2025-23166 high 8.0 1y ago RHSA-2025:8514: nodejs:20 security update (Important)
CVE-2025-23165 high 8.0 1y ago RHSA-2025:8514: nodejs:20 security update (Important)
CVE-2025-4447 high 8.0 1y ago RHSA-2025:8431: java-1.8.0-ibm security update (Important)
CVE-2025-47905 high 8.0 1y ago Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to d…
CVE-2025-5269 high 8.0 1y ago RHSA-2025:8756: thunderbird security update (Important)
CVE-2025-32910 high 8.0 1y ago RHSA-2025:8292: mingw-freetype and spice-client-win security update (Important)
CVE-2025-5264 high 8.0 1y ago Due to insufficient escaping of the newline character in the “Copy as cURL” feature, an attacker could trick a user into using this command, potentially leading to local code execution on the user's …
CVE-2025-5268 high 8.0 1y ago Memory safety bugs present in Firefox 138, Thunderbird 138, Firefox ESR 128.10, and Thunderbird 128.10. Some of these bugs showed evidence of memory corruption and we presume that with enough effort …
CVE-2025-5283 high 8.0 1y ago Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
CVE-2025-5266 high 8.0 1y ago Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability was fixed in Firefox 139, Firefox ESR 128.11, Thu…