2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-65297HIGH7.5Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and...
CVE-2025-65295HIGH8.1Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hu...
CVE-2025-65292HIGH7.3Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4...
CVE-2025-65291HIGH7.4Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certi...
CVE-2025-65290HIGH7.4Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server c...
CVE-2025-67460HIGH7.8Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated u...
CVE-2025-65950HIGH8.8WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged...
CVE-2025-65831HIGH7.5The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hash...
CVE-2025-65824HIGH8.8An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmw...
CVE-2025-65821HIGH7.5As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash fro...
CVE-2025-65512HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markd...
CVE-2025-24857HIGH7.6Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qu...
CVE-2025-63895HIGH7.5An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a...
CVE-2025-65199HIGH7.8A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of...
CVE-2025-56431HIGH7.5Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a deni...
CVE-2025-56430HIGH7.5Directory Traversal vulnerability in Fearless Geek Media FearlessCMS v.0.0.2-15 allows a remote attacker to cause a deni...
CVE-2025-34429HIGH7.11Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration...
CVE-2025-34428HIGH7.8MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local crede...
CVE-2025-34427HIGH7.8MailEnable versions prior to 10.54 contain a cleartext storage of credentials vulnerability that can lead to local crede...
CVE-2025-63094HIGH7.5XiangShan Nanhu V2 and XiangShan Kunmighu V3 were discovered to use speculative execution and indirect branch prediction...
CVE-2025-67635HIGH7.5Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connectio...
CVE-2025-65807HIGH8.4An issue in sd command v1.0.0 and before allows attackers to escalate privileges to root via a crafted command.
CVE-2025-34424HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34423HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...
CVE-2025-34422HIGH7.8MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now