2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13424 | CRITICAL | 9.8 | 0.3% | Nov 20, 2025 | A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file... |
| CVE-2025-13422 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown ... |
| CVE-2025-13421 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown ... |
| CVE-2025-13420 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown pro... |
| CVE-2025-13411 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unk... |
| CVE-2025-13410 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of ... |
| CVE-2025-63213 | CRITICAL | 9.8 | 0.8% | Nov 19, 2025 | The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to imp... |
| CVE-2025-65099 | CRITICAL | 9.8 | 0.4% | Nov 19, 2025 | Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude... |
| CVE-2025-65095 | CRITICAL | 9.4 | 0.3% | Nov 19, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-65026 | CRITICAL | 9.6 | 0.4% | Nov 19, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN servi... |
| CVE-2025-65025 | CRITICAL | 9.8 | 0.5% | Nov 19, 2025 | esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN servi... |
| CVE-2025-65021 | CRITICAL | 9.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-63210 | CRITICAL | 9.8 | 0.5% | Nov 19, 2025 | The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentic... |
| CVE-2025-63207 | CRITICAL | 9.8 | 6.2% | Nov 19, 2025 | The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due... |
| CVE-2025-63206 | CRITICAL | 9.8 | 0.5% | Nov 19, 2025 | An authentication bypass issue was discovered in Dasan Switch DS2924 web based interface, firmware versions 1.01.18 and ... |
| CVE-2025-13315 | CRITICAL | 9.8 | 31.9% | Nov 19, 2025 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass... |
| CVE-2025-34329 | CRITICAL | 9.8 | 1.0% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated ba... |
| CVE-2025-34328 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration... |
| CVE-2025-13400 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtr... |
| CVE-2025-63224 | CRITICAL | 10 | 0.7% | Nov 19, 2025 | The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across ... |
| CVE-2025-63223 | CRITICAL | 9.8 | 0.7% | Nov 19, 2025 | The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control... |
| CVE-2025-63221 | CRITICAL | 9.1 | 0.5% | Nov 19, 2025 | The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missi... |
| CVE-2025-13396 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the f... |
| CVE-2025-63218 | CRITICAL | 9.8 | 0.6% | Nov 19, 2025 | The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Contr... |
| CVE-2025-12592 | CRITICAL | 9.3 | 0.3% | Nov 19, 2025 | Legacy Vivotek Device firmware uses default credetials for the root and user login accounts. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now