2025 CVE Vulnerabilities

45,202 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34330MEDIUM5.3AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration...
CVE-2025-34329CRITICAL9.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated ba...
CVE-2025-34328CRITICAL9.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration...
CVE-2025-13400CRITICAL9.8A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtr...
CVE-2025-12766MEDIUM5An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) versio...
CVE-2025-12743MEDIUM6The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connecti...
CVE-2025-65024HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-65023HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-65022HIGH7.2i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL...
CVE-2025-63879MEDIUM6.1A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 ...
CVE-2025-63878MEDIUM6.5Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form pag...
CVE-2025-63224CRITICAL10The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across ...
CVE-2025-63223CRITICAL9.8The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control...
CVE-2025-63221CRITICAL9.1The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missi...
CVE-2025-63220HIGH7.2The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware up...
CVE-2025-13397MEDIUM5.5A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file s...
CVE-2025-13396CRITICAL9.8A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the f...
CVE-2025-10703HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,...
CVE-2025-10702HIGH8.6Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,...
CVE-2025-63243MEDIUM4.6A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25....
CVE-2025-63219HIGH7.5The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper se...
CVE-2025-63218CRITICAL9.8The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Contr...
CVE-2025-11963MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Comp...
CVE-2025-0421MEDIUM4.7Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allow...
CVE-2025-12592CRITICAL9.3Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now