Skip to main content

Year archive

CVEs published in 2025

Archive summary

48,154 CVEs published in 2025 — 4,091 Critical, 16,156 High, 23,602 Medium, 3,395 Low, 910 Unrated.

CVE-2024-58315

Published Dec 30, 2025

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attac…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-54163

Published Dec 30, 2025

NLB mKlik Macedonia 3.3.12 contains a SQL injection vulnerability in international transfer parameters that allows attackers to manipulate database queries. Attackers can inject a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-50803

Published Dec 30, 2025

JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.

CVSS 9.3 · Critical

CVE-2022-50802

Published Dec 30, 2025

ETAP Safety Manager 1.0.0.32 contains a cross-site scripting vulnerability in the 'action' GET parameter that allows unauthenticated attackers to inject malicious HTML and JavaScr…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-50801

Published Dec 30, 2025

JM-DATA ONU JF511-TV version 1.0.67 is vulnerable to authenticated stored cross-site scripting (XSS) attacks, allowing attackers with authenticated access to inject malicious scri…

CVSS 5.1 · Medium

CVE-2022-50800

Published Dec 30, 2025

H3C SSL VPN contains a user enumeration vulnerability that allows attackers to identify valid usernames through the 'txtUsrName' POST parameter. Attackers can submit different use…

CVSS 6.9 · Medium

CVE-2022-50799

Published Dec 30, 2025

Fetch FTP Client 5.8.2 contains a denial of service vulnerability that allows attackers to trigger 100% CPU consumption by sending long server responses. Attackers can send specia…

CVSS 7.1 · High

CVE-2022-50796

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can ex…

CVSS 9.3 · Critical

CVE-2022-50795

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. U…

CVSS 8.5 · High

CVE-2022-50794

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and logi…

CVSS 9.3 · Critical

CVE-2022-50793

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands th…

CVSS 8.7 · High

CVE-2022-50792

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attack…

CVSS 8.7 · High

CVE-2022-50791

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. U…

CVSS 8.5 · High

CVE-2022-50790

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay…

CVSS 6.9 · Medium

CVE-2022-50789

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid…

CVSS 8.5 · High

CVE-2022-50788

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly br…

CVSS 6.9 · Medium

CVE-2022-50787

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject maliciou…

CVSS 5.3 · Medium

CVE-2022-50696

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers…

CVSS 9.3 · Critical

CVE-2022-50695

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command s…

CVSS 8.7 · High

CVE-2022-50694

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Att…

CVSS 8.8 · High

CVE-2022-50692

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can…

CVSS 6.9 · Medium
Showing 226-250 of 48,154 CVEsPage 10 of 1927