2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34330 | MEDIUM | 5.3 | 0.4% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration... |
| CVE-2025-34329 | CRITICAL | 9.8 | 1.0% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated ba... |
| CVE-2025-34328 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration... |
| CVE-2025-13400 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtr... |
| CVE-2025-12766 | MEDIUM | 5 | 0.2% | Nov 19, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) versio... |
| CVE-2025-12743 | MEDIUM | 6 | 0.2% | Nov 19, 2025 | The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connecti... |
| CVE-2025-65024 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL... |
| CVE-2025-65023 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL... |
| CVE-2025-65022 | HIGH | 7.2 | 0.3% | Nov 19, 2025 | i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL... |
| CVE-2025-63879 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 ... |
| CVE-2025-63878 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form pag... |
| CVE-2025-63224 | CRITICAL | 10 | 0.7% | Nov 19, 2025 | The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across ... |
| CVE-2025-63223 | CRITICAL | 9.8 | 0.7% | Nov 19, 2025 | The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control... |
| CVE-2025-63221 | CRITICAL | 9.1 | 0.5% | Nov 19, 2025 | The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missi... |
| CVE-2025-63220 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware up... |
| CVE-2025-13397 | MEDIUM | 5.5 | 0.1% | Nov 19, 2025 | A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file s... |
| CVE-2025-13396 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the f... |
| CVE-2025-10703 | HIGH | 8.6 | 0.3% | Nov 19, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,... |
| CVE-2025-10702 | HIGH | 8.6 | 0.3% | Nov 19, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,... |
| CVE-2025-63243 | MEDIUM | 4.6 | 0.2% | Nov 19, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.... |
| CVE-2025-63219 | HIGH | 7.5 | 0.4% | Nov 19, 2025 | The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper se... |
| CVE-2025-63218 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Contr... |
| CVE-2025-11963 | MEDIUM | 5.4 | 0.1% | Nov 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Comp... |
| CVE-2025-0421 | MEDIUM | 4.7 | 0.2% | Nov 19, 2025 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allow... |
| CVE-2025-12592 | CRITICAL | 9.3 | 0.3% | Nov 19, 2025 | Legacy Vivotek Device firmware uses default credetials for the root and user login accounts. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now