2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59103CRITICAL9.2The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis...
CVE-2025-59102MEDIUM6.9The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev...
CVE-2025-59101HIGH7.7Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has on...
CVE-2025-59100MEDIUM5.9The web interface offers a functionality to export the internal SQLite database. After executing the database export, an...
CVE-2025-59099HIGH8.8The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a ...
CVE-2025-59098HIGH8.7The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality...
CVE-2025-59097CRITICAL9.3The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done...
CVE-2025-59096MEDIUM4.6The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is...
CVE-2025-59095MEDIUM6.8The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t...
CVE-2025-59094HIGH8.4A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy...
CVE-2025-59093HIGH8.5Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass...
CVE-2025-59092HIGH8.7An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th...
CVE-2025-59091CRITICAL9.3Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn...
CVE-2025-59090CRITICAL9.3On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen...
CVE-2025-41083MEDIUM5.1Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu...
CVE-2025-41082MEDIUM6.9Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m...
CVE-2025-27821HIGH7.3Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 bef...
CVE-2025-14973MEDIUM6.8The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a...
CVE-2025-14316HIGH7.1The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting ...
CVE-2025-71163MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind an...
CVE-2025-71162HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af...
CVE-2025-6461MEDIUM4.3The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers...
CVE-2025-13920MEDIUM5.3The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc...
CVE-2025-15516MEDIUM4.3The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca...
CVE-2025-14907MEDIUM4.3The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now