2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65026 | CRITICAL | 9.6 | 0.4% | Nov 19, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN servi... |
| CVE-2025-65025 | CRITICAL | 9.8 | 0.5% | Nov 19, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN servi... |
| CVE-2025-65021 | CRITICAL | 9.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-65020 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-63210 | CRITICAL | 9.8 | 0.5% | Nov 19, 2025 | The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentic... |
| CVE-2025-63209 | HIGH | 7.5 | 0.4% | Nov 19, 2025 | The ELCA Star Transmitter Remote Control firmware 1.25 for STAR150, BP1000, STAR300, STAR2000, STAR1000, STAR500, and po... |
| CVE-2025-63208 | HIGH | 7.5 | 0.2% | Nov 19, 2025 | An issue was discovered in bridgetech VB288 Objective QoE Content Extractor, firmware version 5.6.0-8, allowing attacker... |
| CVE-2025-63207 | CRITICAL | 9.8 | 6.2% | Nov 19, 2025 | The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due... |
| CVE-2025-63206 | CRITICAL | 9.8 | 0.5% | Nov 19, 2025 | An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and ... |
| CVE-2025-63205 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | An issue was discovered in bridgetech probes VB220 IP Network Probe,VB120 Embedded IP + RF Probe, VB330 High-Capacity Pr... |
| CVE-2025-13316 | HIGH | 8.1 | 2.6% | Nov 19, 2025 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An... |
| CVE-2025-13315 | CRITICAL | 9.8 | 31.9% | Nov 19, 2025 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass... |
| CVE-2025-65019 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with outp... |
| CVE-2025-64765 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for rout... |
| CVE-2025-64764 | MEDIUM | 5.4 | 0.4% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feat... |
| CVE-2025-64757 | LOW | 3.5 | 0.4% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's developm... |
| CVE-2025-64708 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions,... |
| CVE-2025-64521 | MEDIUM | 4.8 | 0.2% | Nov 19, 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client... |
| CVE-2025-34337 | HIGH | 8.7 | 0.3% | Nov 19, 2025 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and relate... |
| CVE-2025-34336 | MEDIUM | 6.9 | 0.5% | Nov 19, 2025 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vuln... |
| CVE-2025-34335 | HIGH | 8.8 | 2.6% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated comm... |
| CVE-2025-34334 | HIGH | 8.8 | 3.1% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authent... |
| CVE-2025-34333 | HIGH | 7.8 | 0.2% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document r... |
| CVE-2025-34332 | HIGH | 7.8 | 0.2% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration... |
| CVE-2025-34331 | HIGH | 7.5 | 0.5% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 contain an unauthenticated f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now