2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14485 | MEDIUM | 5 | 1.6% | Dec 11, 2025 | A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen o... |
| CVE-2025-11467 | MEDIUM | 5.8 | 0.3% | Dec 11, 2025 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2025-67720 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | Pyrofork is a modern, asynchronous MTProto API framework. Versions 2.3.68 and earlier do not properly sanitize filenames... |
| CVE-2025-67717 | MEDIUM | 4.3 | 0.2% | Dec 11, 2025 | ZITADEL is an open-source identity infrastructure tool. Versions 2.44.0 through 3.4.4 and 4.0.0-rc.1 through 4.7.1 discl... |
| CVE-2025-67716 | MEDIUM | 5.7 | 0.2% | Dec 11, 2025 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions 4.9.0 through ... |
| CVE-2025-67713 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs... |
| CVE-2025-67648 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | Shopware is an open commerce platform. Versions 6.4.6.0 through 6.6.10.9 and 6.7.0.0 through 6.7.5.0 have a Reflected XS... |
| CVE-2025-67513 | MEDIUM | 6.9 | 0.3% | Dec 10, 2025 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and ... |
| CVE-2025-67490 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.1... |
| CVE-2025-66472 | MEDIUM | 6.1 | 0.5% | Dec 10, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-mi... |
| CVE-2025-66033 | MEDIUM | 5.3 | 0.3% | Dec 10, 2025 | Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, speci... |
| CVE-2025-65296 | MEDIUM | 6.5 | 0.3% | Dec 10, 2025 | NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in ... |
| CVE-2025-65293 | MEDIUM | 6.6 | 1.1% | Dec 10, 2025 | Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with r... |
| CVE-2025-67461 | MEDIUM | 5.5 | 0.1% | Dec 10, 2025 | External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to co... |
| CVE-2025-65832 | MEDIUM | 4.6 | 0.1% | Dec 10, 2025 | The mobile application insecurely handles information stored within memory. By performing a memory dump on the applicati... |
| CVE-2025-65829 | MEDIUM | 6.8 | 0.3% | Dec 10, 2025 | The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure B... |
| CVE-2025-65828 | MEDIUM | 6.5 | 0.3% | Dec 10, 2025 | An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy... |
| CVE-2025-65825 | MEDIUM | 4.6 | 0.1% | Dec 10, 2025 | The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet devi... |
| CVE-2025-65822 | MEDIUM | 6.8 | 0.2% | Dec 10, 2025 | The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on... |
| CVE-2025-62181 | MEDIUM | 5.3 | — | Dec 10, 2025 | Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user ... |
| CVE-2025-64888 | MEDIUM | 5.4 | — | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-64887 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit... |
| CVE-2025-64881 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-64875 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-64873 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now