2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67648MEDIUM6.1Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XS...
CVE-2025-67513MEDIUM6.9FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and ...
CVE-2025-67490MEDIUM5.4The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.1...
CVE-2025-66472MEDIUM6.1XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-mi...
CVE-2025-66033MEDIUM5.3Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, speci...
CVE-2025-65296MEDIUM6.5NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in ...
CVE-2025-65293MEDIUM6.6Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with r...
CVE-2025-67461MEDIUM5.5External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to co...
CVE-2025-65832MEDIUM4.6The mobile application insecurely handles information stored within memory. By performing a memory dump on the applicati...
CVE-2025-65829MEDIUM6.8The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure B...
CVE-2025-65828MEDIUM6.5An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy...
CVE-2025-65825MEDIUM4.6The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet devi...
CVE-2025-65822MEDIUM6.8The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on...
CVE-2025-62181MEDIUM5.3Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user ...
CVE-2025-64888MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64887MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64881MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64875MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64873MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64872MEDIUM4.8Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64869MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64863MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64861MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64858MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64857MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now