2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-66123MEDIUM5.3Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
CVE-2025-64637MEDIUM5.3Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
CVE-2025-64636MEDIUM5.3Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
CVE-2025-63079MEDIUM4.3Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
CVE-2025-63078MEDIUM4.3Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
CVE-2025-63041MEDIUM5.4Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
CVE-2025-64152CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2025-55017CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2025-7958HIGH7.1A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe...
CVE-2025-10268MEDIUM5.3The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path travers...
CVE-2025-71340HIGH8.1picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode...
CVE-2025-71338CRITICAL9.8Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauth...
CVE-2025-71336CRITICAL9.8Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera...
CVE-2025-71335HIGH8.6Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens aft...
CVE-2025-71334CRITICAL9.8Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin...
CVE-2025-71333CRITICAL9.8Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin...
CVE-2025-71328HIGH8.8Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their accou...
CVE-2025-71327CRITICAL9.3Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows...
CVE-2025-71324HIGH8.7Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil...
CVE-2025-60465MEDIUM6.1A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02...
CVE-2025-60464HIGH7.8A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26....
CVE-2025-60473MEDIUM5.5A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ...
CVE-2025-60466MEDIUM5A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0...
CVE-2025-8106Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-60474HIGH7.5A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now