2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59107HIGH8.5Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The...
CVE-2025-59106HIGH8.8The binary serving the web server and executing basically all actions launched from the Web UI is running with root priv...
CVE-2025-59105HIGH7With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinsta...
CVE-2025-59104HIGH7With physical access to the device and enough time an attacker is able to solder test leads to the debug footprint (or u...
CVE-2025-59103CRITICAL9.2The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis...
CVE-2025-59102MEDIUM6.9The web server of the Access Manager offers a functionality to download a backup of the local database stored on the dev...
CVE-2025-59101HIGH7.7Instead of typical session tokens or cookies, it is verified on a per-request basis if the originating IP address has on...
CVE-2025-59100MEDIUM5.9The web interface offers a functionality to export the internal SQLite database. After executing the database export, an...
CVE-2025-59099HIGH8.8The Access Manager is using the open source web server CompactWebServer written in C#. This web server is affected by a ...
CVE-2025-59098HIGH8.7The Access Manager is offering a trace functionality to debug errors and issues with the device. The trace functionality...
CVE-2025-59097CRITICAL9.3The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done...
CVE-2025-59096MEDIUM4.6The default password for the extended admin user mode in the application U9ExosAdmin.exe ("Kaba 9300 Administration") is...
CVE-2025-59095MEDIUM6.8The program libraries (DLL) and binaries used by exos 9300 contain multiple hard-coded secrets. One notable example is t...
CVE-2025-59094HIGH8.4A local privilege escalation vulnerability has been identified in the Kaba exos 9300 System management application (d9sy...
CVE-2025-59093HIGH8.5Exos 9300 instances are using a randomly generated database password to connect to the configured MSSQL server. The pass...
CVE-2025-59092HIGH8.7An RPC service, which is part of exos 9300, is reachable on port 4000, run by the process FSMobilePhoneInterface.exe. Th...
CVE-2025-59091CRITICAL9.3Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn...
CVE-2025-59090CRITICAL9.3On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen...
CVE-2025-41083MEDIUM5.1Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipu...
CVE-2025-41082MEDIUM6.9Illegal HTTP request traffic vulnerability (CL.0) in Altitude Communication Server, caused by inconsistent analysis of m...
CVE-2025-27821HIGH7.3Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client. This issue affects Apache Hadoop: from 3.2.0 bef...
CVE-2025-14973MEDIUM6.8The Recipe Card Blocks Lite WordPress plugin before 3.4.13 does not sanitize and escape a parameter before using it in a...
CVE-2025-14316HIGH7.1The AhaChat Messenger Marketing WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting ...
CVE-2025-71163MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: fix device leaks on compat bind an...
CVE-2025-71162HIGH7.8In the Linux kernel, the following vulnerability has been resolved: dmaengine: tegra-adma: Fix use-after-free A use-af...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now