2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66123 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions. |
| CVE-2025-64637 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | Unauthenticated Content Injection in Auros Core <= 5.3.1 versions. |
| CVE-2025-64636 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions. |
| CVE-2025-63079 | MEDIUM | 4.3 | — | Jun 26, 2026 | Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions. |
| CVE-2025-63078 | MEDIUM | 4.3 | — | Jun 26, 2026 | Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions. |
| CVE-2025-63041 | MEDIUM | 5.4 | — | Jun 26, 2026 | Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions. |
| CVE-2025-64152 | CRITICAL | 9.1 | — | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu... |
| CVE-2025-55017 | CRITICAL | 9.1 | — | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu... |
| CVE-2025-7958 | HIGH | 7.1 | — | Jun 26, 2026 | A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe... |
| CVE-2025-10268 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path travers... |
| CVE-2025-71340 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode... |
| CVE-2025-71338 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauth... |
| CVE-2025-71336 | CRITICAL | 9.8 | 0.7% | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera... |
| CVE-2025-71335 | HIGH | 8.6 | 0.3% | Jun 25, 2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens aft... |
| CVE-2025-71334 | CRITICAL | 9.8 | 0.9% | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin... |
| CVE-2025-71333 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin... |
| CVE-2025-71328 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their accou... |
| CVE-2025-71327 | CRITICAL | 9.3 | 0.5% | Jun 25, 2026 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows... |
| CVE-2025-71324 | HIGH | 8.7 | 0.3% | Jun 25, 2026 | Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil... |
| CVE-2025-60465 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02... |
| CVE-2025-60464 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.... |
| CVE-2025-60473 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ... |
| CVE-2025-60466 | MEDIUM | 5 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0... |
| CVE-2025-8106 | — | — | — | Jun 24, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-60474 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now