2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10437 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electroni... |
| CVE-2025-12057 | CRITICAL | 9.8 | 0.4% | Nov 19, 2025 | The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate ... |
| CVE-2025-13051 | CRITICAL | 9.3 | 0.2% | Nov 19, 2025 | When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replac... |
| CVE-2025-64325 | CRITICAL | 9 | 0.4% | Nov 18, 2025 | Emby Server is a personal media server. Prior to version 4.8.1.0 and prior to Beta version 4.9.0.0-beta, a malicious use... |
| CVE-2025-63217 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across dev... |
| CVE-2025-63216 | CRITICAL | 10 | 0.7% | Nov 18, 2025 | The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across... |
| CVE-2025-63228 | CRITICAL | 9.8 | 0.7% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vu... |
| CVE-2025-63225 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing au... |
| CVE-2025-54321 | CRITICAL | 9.8 | 0.4% | Nov 18, 2025 | In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an ema... |
| CVE-2025-63695 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php. |
| CVE-2025-63694 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage. |
| CVE-2025-56643 | CRITICAL | 9.1 | 0.3% | Nov 18, 2025 | Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, pre... |
| CVE-2025-9312 | CRITICAL | 9.8 | 0.2% | Nov 18, 2025 | A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST AP... |
| CVE-2025-41348 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover,... |
| CVE-2025-13344 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is a... |
| CVE-2025-41734 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices. |
| CVE-2025-41733 | CRITICAL | 9.8 | 0.6% | Nov 18, 2025 | The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthentica... |
| CVE-2025-41347 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerabili... |
| CVE-2025-41346 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impers... |
| CVE-2025-40549 | CRITICAL | 9.1 | 1.0% | Nov 18, 2025 | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to a... |
| CVE-2025-40548 | CRITICAL | 9.1 | 0.6% | Nov 18, 2025 | A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges ... |
| CVE-2025-40547 | CRITICAL | 9.1 | 0.8% | Nov 18, 2025 | A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privile... |
| CVE-2025-13323 | CRITICAL | 9.8 | 0.4% | Nov 18, 2025 | A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function o... |
| CVE-2025-13305 | CRITICAL | 9.8 | 3.2% | Nov 17, 2025 | A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects... |
| CVE-2025-13303 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown fu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now