2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66033MEDIUM5.3Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, speci...
CVE-2025-65297HIGH7.5Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and...
CVE-2025-65296MEDIUM6.5NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in ...
CVE-2025-65295HIGH8.1Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hu...
CVE-2025-65294CRITICAL9.8Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented r...
CVE-2025-65293MEDIUM6.6Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with r...
CVE-2025-65292HIGH7.3Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4...
CVE-2025-65291HIGH7.4Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certi...
CVE-2025-65290HIGH7.4Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server c...
CVE-2025-67461MEDIUM5.5External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to co...
CVE-2025-67460HIGH7.8Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated u...
CVE-2025-65950HIGH8.8WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged...
CVE-2025-65832MEDIUM4.6The mobile application insecurely handles information stored within memory. By performing a memory dump on the applicati...
CVE-2025-65831HIGH7.5The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hash...
CVE-2025-65830CRITICAL9.1Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adv...
CVE-2025-65829MEDIUM6.8The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure B...
CVE-2025-65828MEDIUM6.5An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy...
CVE-2025-65827CRITICAL9.1The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over...
CVE-2025-65826CRITICAL9.8The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retri...
CVE-2025-65825MEDIUM4.6The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet devi...
CVE-2025-65824HIGH8.8An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmw...
CVE-2025-65823CRITICAL9.8The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was d...
CVE-2025-65822MEDIUM6.8The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on...
CVE-2025-65821HIGH7.5As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash fro...
CVE-2025-65820CRITICAL9.8An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mob...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now