2025 CVE Vulnerabilities
45,334 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67511 | CRITICAL | 9.6 | 1.8% | Dec 11, 2025 | Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automat... |
| CVE-2025-67513 | MEDIUM | 6.9 | 0.3% | Dec 10, 2025 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and ... |
| CVE-2025-67510 | CRITICAL | 9.4 | 0.4% | Dec 10, 2025 | Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool exe... |
| CVE-2025-67509 | HIGH | 8.2 | 0.3% | Dec 10, 2025 | Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which... |
| CVE-2025-67505 | HIGH | 8.4 | 0.2% | Dec 10, 2025 | Okta Java Management SDK facilitates interactions with the Okta management API. In versions 11.0.0 through 20.0.0, race ... |
| CVE-2025-67490 | MEDIUM | 5.4 | 0.2% | Dec 10, 2025 | The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. When using versions 4.1... |
| CVE-2025-13923 | — | — | — | Dec 10, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12731 | — | — | — | Dec 10, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-66628 | HIGH | 7.5 | 0.5% | Dec 10, 2025 | ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the T... |
| CVE-2025-66474 | HIGH | 8.8 | 1.0% | Dec 10, 2025 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-66473 | HIGH | 7.5 | 0.4% | Dec 10, 2025 | XWiki is an open-source wiki software platform. Versions 16.10.10 and below, 17.0.0-rc-1 through 17.4.3 and 17.5.0-rc-1 ... |
| CVE-2025-66472 | MEDIUM | 6.1 | 0.5% | Dec 10, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Versions 6.2-mi... |
| CVE-2025-66033 | MEDIUM | 5.3 | 0.3% | Dec 10, 2025 | Okta Java Management SDK facilitates interactions with the Okta management API. In versions 21.0.0 through 24.0.0, speci... |
| CVE-2025-65297 | HIGH | 7.5 | 0.2% | Dec 10, 2025 | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 automatically collect and... |
| CVE-2025-65296 | MEDIUM | 6.5 | 0.3% | Dec 10, 2025 | NULL-pointer dereference vulnerabilities in Aqara Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, and Camera Hub G3 4.1.9_0027 in ... |
| CVE-2025-65295 | HIGH | 8.1 | 0.2% | Dec 10, 2025 | Multiple vulnerabilities in Aqara Hub firmware update process in the Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hu... |
| CVE-2025-65294 | CRITICAL | 9.8 | 1.0% | Dec 10, 2025 | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented r... |
| CVE-2025-65293 | MEDIUM | 6.6 | 1.1% | Dec 10, 2025 | Command injection vulnerabilities in Aqara Camera Hub G3 4.1.9_0027 allow attackers to execute arbitrary commands with r... |
| CVE-2025-65292 | HIGH | 7.3 | 0.8% | Dec 10, 2025 | Command injection vulnerability in Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4... |
| CVE-2025-65291 | HIGH | 7.4 | 0.2% | Dec 10, 2025 | Aqara Hub devices including Hub M2 4.3.6_0027, Hub M3 4.3.6_0025, Camera Hub G3 4.1.9_0027 fail to validate server certi... |
| CVE-2025-65290 | HIGH | 7.4 | 0.2% | Dec 10, 2025 | Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 fail to validate server c... |
| CVE-2025-67461 | MEDIUM | 5.5 | 0.1% | Dec 10, 2025 | External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to co... |
| CVE-2025-67460 | HIGH | 7.8 | 0.2% | Dec 10, 2025 | Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated u... |
| CVE-2025-65950 | HIGH | 8.8 | 0.5% | Dec 10, 2025 | WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged... |
| CVE-2025-65832 | MEDIUM | 4.6 | 0.1% | Dec 10, 2025 | The mobile application insecurely handles information stored within memory. By performing a memory dump on the applicati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now