2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65029HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ...
CVE-2025-63209HIGH7.5The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and po...
CVE-2025-63208HIGH7.5An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attacker...
CVE-2025-63205HIGH7.5An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Pr...
CVE-2025-13316HIGH8.1Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An...
CVE-2025-34337HIGH8.7eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and relate...
CVE-2025-34335HIGH8.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated comm...
CVE-2025-34334HIGH8.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authent...
CVE-2025-34333HIGH7.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document r...
CVE-2025-34332HIGH7.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration...
CVE-2025-34331HIGH7.5AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated f...
CVE-2025-65024HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-65023HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-65022HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-63220HIGH7.2The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware up...
CVE-2025-10703HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,...
CVE-2025-10702HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,...
CVE-2025-63219HIGH7.5The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper se...
CVE-2025-13395HIGH7.3A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted el...
CVE-2025-12472HIGH7.1An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git direct...
CVE-2025-11230HIGH7.5Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially ...
CVE-2025-13035HIGH8The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. ...
CVE-2025-12484HIGH7.2The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for...
CVE-2025-12056HIGH8.3Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers.
CVE-2025-11243HIGH8.3Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now