2025 CVE Vulnerabilities

45,334 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65831HIGH7.5The application uses an insecure hashing algorithm (MD5) to hash passwords. If an attacker obtained a copy of these hash...
CVE-2025-65830CRITICAL9.1Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adv...
CVE-2025-65829MEDIUM6.8The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure B...
CVE-2025-65828MEDIUM6.5An unauthenticated attacker within proximity of the Meatmeet device can issue several commands over Bluetooth Low Energy...
CVE-2025-65827CRITICAL9.1The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over...
CVE-2025-65826CRITICAL9.8The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retri...
CVE-2025-65825MEDIUM4.6The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet devi...
CVE-2025-65824HIGH8.8An unauthenticated attacker within proximity of the Meatmeet device can perform an unauthorized Over The Air (OTA) firmw...
CVE-2025-65823CRITICAL9.8The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was d...
CVE-2025-65822MEDIUM6.8The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on...
CVE-2025-65821HIGH7.5As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash fro...
CVE-2025-65820CRITICAL9.8An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mob...
CVE-2025-65512HIGH7.5A Server-Side Request Forgery (SSRF) vulnerability was discovered in the webpage-to-markdown conversion feature of markd...
CVE-2025-62181MEDIUM5.3Pega Platform versions 7.1.0 through Infinity 25.1.0 are affected by a User Enumeration. This issue occurs during user ...
CVE-2025-24857HIGH7.6Improper access control for volatile memory containing boot code in Universal Boot Loader (U-Boot) before 2017.11 and Qu...
CVE-2025-65602CRITICAL9.8A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbi...
CVE-2025-63895HIGH7.5An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a...
CVE-2025-65199HIGH7.8A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of...
CVE-2025-64888MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64887MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64881MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64875MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64873MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64872MEDIUM4.8Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-64869MEDIUM5.4Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now