2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15681CRITICAL9.2TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic...
CVE-2025-15680LOW2.4TBEA TLogger V2.1.0.0B0.0.0.0 exposes a UART interface on the device's circuit board without sufficient protection. A ph...
CVE-2025-13294CRITICAL9.3An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP ...
CVE-2025-13293CRITICAL9.3A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack...
CVE-2025-4438Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71413MEDIUM6Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets w...
CVE-2025-71412HIGH7.1Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion...
CVE-2025-71411MEDIUM6Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic c...
CVE-2025-71410MEDIUM6Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and...
CVE-2025-71409HIGH7.1Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages ...
CVE-2025-63235HIGH7.5In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CON...
CVE-2025-6508MEDIUM4.3The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to b...
CVE-2025-15674LOW2.7The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from ...
CVE-2025-14561CRITICAL9In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o...
CVE-2025-12317MEDIUM5When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue...
CVE-2025-49506HIGH7.5APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or p...
CVE-2025-9266MEDIUM4.3The Accelerate theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ...
CVE-2025-15028HIGH7.2The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is ...
CVE-2025-15039CRITICAL9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require...
CVE-2025-14779LOW3.8The Secret Type Management REST API does not correctly isolate access controls when deleting a secret type. The on-delet...
CVE-2025-13909MEDIUM4.3The system accepts authentication requests without sufficient validation to enforce tenant isolation when using Email OT...
CVE-2025-13736LOW3.7When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo...
CVE-2025-13394MEDIUM5.4The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Reque...
CVE-2025-12627LOW2.4The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated...
CVE-2025-11850MEDIUM4.3When secondary user stores are configured, the implicit-association resolver incorrectly initializes from a secondary us...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now