2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-63371HIGH7.5Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file p...
CVE-2025-65103HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an ...
CVE-2025-63932HIGH7.3D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary...
CVE-2025-51663HIGH7.5A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based ...
CVE-2025-51661HIGH7.5A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is co...
CVE-2025-65094HIGH8.8WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their pr...
CVE-2025-65034HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerabil...
CVE-2025-65033HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll ma...
CVE-2025-65030HIGH7.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment...
CVE-2025-65029HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ...
CVE-2025-63209HIGH7.5The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and po...
CVE-2025-63208HIGH7.5An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attacker...
CVE-2025-63205HIGH7.5An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Pr...
CVE-2025-13316HIGH8.1Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An...
CVE-2025-34337HIGH8.7eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and relate...
CVE-2025-34335HIGH8.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated comm...
CVE-2025-34334HIGH8.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authent...
CVE-2025-34333HIGH7.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document r...
CVE-2025-34332HIGH7.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration...
CVE-2025-34331HIGH7.5AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated f...
CVE-2025-65024HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-65023HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-65022HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-63220HIGH7.2The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware up...
CVE-2025-10703HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now