2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-13315CRITICAL9.8Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass...
CVE-2025-34329CRITICAL9.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated ba...
CVE-2025-34328CRITICAL9.8AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration...
CVE-2025-13400CRITICAL9.8A vulnerability was detected in Tenda CH22 1.0.0.1. Affected is the function formWrlExtraGet of the file /goform/WrlExtr...
CVE-2025-63224CRITICAL10The Itel DAB Encoder (IDEnc build 25aec8d) is vulnerable to Authentication Bypass due to improper JWT validation across ...
CVE-2025-63223CRITICAL9.8The Axel Technology StreamerMAX MK II devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control...
CVE-2025-63221CRITICAL9.1The Axel Technology puma devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Control due to missi...
CVE-2025-13396CRITICAL9.8A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the f...
CVE-2025-63218CRITICAL9.8The Axel Technology WOLF1MS and WOLF2MS devices (firmware versions 0.8.5 to 1.0.3) are vulnerable to Broken Access Contr...
CVE-2025-12592CRITICAL9.3Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.
CVE-2025-10437CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electroni...
CVE-2025-12057CRITICAL9.8The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate ...
CVE-2025-13051CRITICAL9.3When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replac...
CVE-2025-64325CRITICAL9Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious use...
CVE-2025-63217CRITICAL9.8The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across dev...
CVE-2025-63216CRITICAL10The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across...
CVE-2025-63228CRITICAL9.8The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vu...
CVE-2025-63225CRITICAL9.8The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing au...
CVE-2025-54321CRITICAL9.8In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an ema...
CVE-2025-63695CRITICAL9.8DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.
CVE-2025-63694CRITICAL9.8DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.
CVE-2025-56643CRITICAL9.1Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, pre...
CVE-2025-9312CRITICAL9.8A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST AP...
CVE-2025-41348CRITICAL9.8SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover,...
CVE-2025-13344CRITICAL9.8A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now