2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65029 | HIGH | 8.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ... |
| CVE-2025-63209 | HIGH | 7.5 | 0.4% | Nov 19, 2025 | The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and po... |
| CVE-2025-63208 | HIGH | 7.5 | 0.2% | Nov 19, 2025 | An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attacker... |
| CVE-2025-63205 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Pr... |
| CVE-2025-13316 | HIGH | 8.1 | 2.6% | Nov 19, 2025 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An... |
| CVE-2025-34337 | HIGH | 8.7 | 0.3% | Nov 19, 2025 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and relate... |
| CVE-2025-34335 | HIGH | 8.8 | 2.6% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated comm... |
| CVE-2025-34334 | HIGH | 8.8 | 3.1% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authent... |
| CVE-2025-34333 | HIGH | 7.8 | 0.2% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document r... |
| CVE-2025-34332 | HIGH | 7.8 | 0.2% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration... |
| CVE-2025-34331 | HIGH | 7.5 | 0.5% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated f... |
| CVE-2025-65024 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL... |
| CVE-2025-65023 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL... |
| CVE-2025-65022 | HIGH | 7.2 | 0.3% | Nov 19, 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL... |
| CVE-2025-63220 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware up... |
| CVE-2025-10703 | HIGH | 8.6 | 0.3% | Nov 19, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,... |
| CVE-2025-10702 | HIGH | 8.6 | 0.3% | Nov 19, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,... |
| CVE-2025-63219 | HIGH | 7.5 | 0.4% | Nov 19, 2025 | The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper se... |
| CVE-2025-13395 | HIGH | 7.3 | 0.3% | Nov 19, 2025 | A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted el... |
| CVE-2025-12472 | HIGH | 7.1 | 0.2% | Nov 19, 2025 | An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git direct... |
| CVE-2025-11230 | HIGH | 7.5 | 0.5% | Nov 19, 2025 | Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially ... |
| CVE-2025-13035 | HIGH | 8 | 0.3% | Nov 19, 2025 | The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. ... |
| CVE-2025-12484 | HIGH | 7.2 | 0.3% | Nov 19, 2025 | The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for... |
| CVE-2025-12056 | HIGH | 8.3 | 0.2% | Nov 19, 2025 | Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers. |
| CVE-2025-11243 | HIGH | 8.3 | 0.4% | Nov 19, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now