2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15681 | CRITICAL | 9.2 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic... |
| CVE-2025-15680 | LOW | 2.4 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph... |
| CVE-2025-13294 | CRITICAL | 9.3 | — | Aug 10, 2026 | An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP ... |
| CVE-2025-13293 | CRITICAL | 9.3 | — | Aug 10, 2026 | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack... |
| CVE-2025-4438 | — | — | — | Aug 7, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-71413 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w... |
| CVE-2025-71412 | HIGH | 7.1 | 0.2% | Aug 7, 2026 | Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion... |
| CVE-2025-71411 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c... |
| CVE-2025-71410 | MEDIUM | 6 | 0.2% | Aug 7, 2026 | Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and... |
| CVE-2025-71409 | HIGH | 7.1 | 0.2% | Aug 7, 2026 | Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages ... |
| CVE-2025-63235 | HIGH | 7.5 | — | Aug 7, 2026 | In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON... |
| CVE-2025-6508 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b... |
| CVE-2025-15674 | LOW | 2.7 | 0.2% | Aug 6, 2026 | The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from ... |
| CVE-2025-14561 | CRITICAL | 9 | 0.4% | Aug 6, 2026 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o... |
| CVE-2025-12317 | MEDIUM | 5 | 0.2% | Aug 6, 2026 | When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue... |
| CVE-2025-49506 | HIGH | 7.5 | 0.3% | Aug 6, 2026 | APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p... |
| CVE-2025-9266 | MEDIUM | 4.3 | — | Aug 6, 2026 | The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-15028 | HIGH | 7.2 | — | Aug 6, 2026 | The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is ... |
| CVE-2025-15039 | CRITICAL | 9.4 | 0.4% | Aug 6, 2026 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require... |
| CVE-2025-14779 | LOW | 3.8 | 0.2% | Aug 6, 2026 | The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet... |
| CVE-2025-13909 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT... |
| CVE-2025-13736 | LOW | 3.7 | 0.2% | Aug 6, 2026 | When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo... |
| CVE-2025-13394 | MEDIUM | 5.4 | 0.1% | Aug 6, 2026 | The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque... |
| CVE-2025-12627 | LOW | 2.4 | 0.1% | Aug 6, 2026 | The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated... |
| CVE-2025-11850 | MEDIUM | 4.3 | 0.2% | Aug 6, 2026 | When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now