2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-64701HIGH8.5QND Premium/Advance/Standard Ver.11.0.9i and prior contains a privilege escalation vulnerability, which may allow a user...
CVE-2025-12029HIGH8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and ...
CVE-2025-67738HIGH8.5squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module a...
CVE-2025-8405HIGH7.7GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5....
CVE-2025-12716HIGH8.7GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 1...
CVE-2025-12562HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and ...
CVE-2025-67719HIGH8.5Ibexa is a composable end-to-end DXP (Digital Experience Platform). Versions 5.0.0-beta1 through 5.0.3 do not have passw...
CVE-2025-67718HIGH8.7Form.io is a combined Form and API platform for Serverless applications. Versions 3.5.6 and below and 4.0.0-rc.1 through...
CVE-2025-67644HIGH7.8LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ...
CVE-2025-67509HIGH8.2Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which...
CVE-2025-67505HIGH8.4Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race ...
CVE-2025-66628HIGH7.5ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the T...
CVE-2025-66474HIGH8.8XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int...
CVE-2025-66473HIGH7.5XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 ...
CVE-2025-65297HIGH7.5Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and...
CVE-2025-65295HIGH8.1Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hu...
CVE-2025-65292HIGH7.3Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4...
CVE-2025-65291HIGH7.4Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certi...
CVE-2025-65290HIGH7.4Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server c...
CVE-2025-67460HIGH7.8Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated u...
CVE-2025-65950HIGH8.8WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged...
CVE-2025-65831HIGH7.5The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hash...
CVE-2025-65824HIGH8.8An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmw...
CVE-2025-65821HIGH7.5As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash fro...
CVE-2025-65512HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markd...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now