2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13315 | CRITICAL | 9.8 | 31.9% | Nov 19, 2025 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass... |
| CVE-2025-34329 | CRITICAL | 9.8 | 1.0% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated ba... |
| CVE-2025-34328 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration... |
| CVE-2025-13400 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtr... |
| CVE-2025-63224 | CRITICAL | 10 | 0.7% | Nov 19, 2025 | The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across ... |
| CVE-2025-63223 | CRITICAL | 9.8 | 0.7% | Nov 19, 2025 | The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control... |
| CVE-2025-63221 | CRITICAL | 9.1 | 0.5% | Nov 19, 2025 | The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missi... |
| CVE-2025-13396 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the f... |
| CVE-2025-63218 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Contr... |
| CVE-2025-12592 | CRITICAL | 9.3 | 0.3% | Nov 19, 2025 | Legacy Vivotek Device firmware uses default credetials for the root and user login accounts. |
| CVE-2025-10437 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electroni... |
| CVE-2025-12057 | CRITICAL | 9.8 | 0.4% | Nov 19, 2025 | The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate ... |
| CVE-2025-13051 | CRITICAL | 9.3 | 0.2% | Nov 19, 2025 | When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replac... |
| CVE-2025-64325 | CRITICAL | 9 | 0.4% | Nov 18, 2025 | Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious use... |
| CVE-2025-63217 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across dev... |
| CVE-2025-63216 | CRITICAL | 10 | 0.7% | Nov 18, 2025 | The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across... |
| CVE-2025-63228 | CRITICAL | 9.8 | 0.7% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vu... |
| CVE-2025-63225 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing au... |
| CVE-2025-54321 | CRITICAL | 9.8 | 0.4% | Nov 18, 2025 | In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an ema... |
| CVE-2025-63695 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php. |
| CVE-2025-63694 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage. |
| CVE-2025-56643 | CRITICAL | 9.1 | 0.3% | Nov 18, 2025 | Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, pre... |
| CVE-2025-9312 | CRITICAL | 9.8 | 0.2% | Nov 18, 2025 | A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST AP... |
| CVE-2025-41348 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover,... |
| CVE-2025-13344 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now