2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59103 | CRITICAL | 9.2 | 0.4% | Jan 26, 2026 | The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis... |
| CVE-2025-59102 | MEDIUM | 6.9 | 0.3% | Jan 26, 2026 | The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev... |
| CVE-2025-59101 | HIGH | 7.7 | 0.6% | Jan 26, 2026 | Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has on... |
| CVE-2025-59100 | MEDIUM | 5.9 | 0.6% | Jan 26, 2026 | The web interface offers a functionality to export the internal SQLite database. After executing the database export, an... |
| CVE-2025-59099 | HIGH | 8.8 | 0.7% | Jan 26, 2026 | The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a ... |
| CVE-2025-59098 | HIGH | 8.7 | 0.3% | Jan 26, 2026 | The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality... |
| CVE-2025-59097 | CRITICAL | 9.3 | 0.5% | Jan 26, 2026 | The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done... |
| CVE-2025-59096 | MEDIUM | 4.6 | 0.2% | Jan 26, 2026 | The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is... |
| CVE-2025-59095 | MEDIUM | 6.8 | 0.1% | Jan 26, 2026 | The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t... |
| CVE-2025-59094 | HIGH | 8.4 | 0.2% | Jan 26, 2026 | A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy... |
| CVE-2025-59093 | HIGH | 8.5 | 0.2% | Jan 26, 2026 | Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass... |
| CVE-2025-59092 | HIGH | 8.7 | 0.8% | Jan 26, 2026 | An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th... |
| CVE-2025-59091 | CRITICAL | 9.3 | 0.8% | Jan 26, 2026 | Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn... |
| CVE-2025-59090 | CRITICAL | 9.3 | 1.0% | Jan 26, 2026 | On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen... |
| CVE-2025-41083 | MEDIUM | 5.1 | 0.4% | Jan 26, 2026 | Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu... |
| CVE-2025-41082 | MEDIUM | 6.9 | 0.4% | Jan 26, 2026 | Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m... |
| CVE-2025-27821 | HIGH | 7.3 | 0.9% | Jan 26, 2026 | Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 bef... |
| CVE-2025-14973 | MEDIUM | 6.8 | 0.3% | Jan 26, 2026 | The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a... |
| CVE-2025-14316 | HIGH | 7.1 | 0.2% | Jan 26, 2026 | The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting ... |
| CVE-2025-71163 | MEDIUM | 5.5 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind an... |
| CVE-2025-71162 | HIGH | 7.8 | 0.2% | Jan 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af... |
| CVE-2025-6461 | MEDIUM | 4.3 | 0.2% | Jan 25, 2026 | The CubeWP – All-in-One Dynamic Content Framework plugin for WordPress is vulnerable to Information Exposure in all vers... |
| CVE-2025-13920 | MEDIUM | 5.3 | 0.7% | Jan 24, 2026 | The WP Directory Kit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc... |
| CVE-2025-15516 | MEDIUM | 4.3 | 0.2% | Jan 24, 2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-14907 | MEDIUM | 4.3 | 0.1% | Jan 24, 2026 | The Moderate Selected Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now