2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60467 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ... |
| CVE-2025-60468 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflo... |
| CVE-2025-64719 | MEDIUM | 4.9 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a ... |
| CVE-2025-60471 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4B... |
| CVE-2025-71361 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem... |
| CVE-2025-71354 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun... |
| CVE-2025-71332 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation ... |
| CVE-2025-64105 | MEDIUM | 5.1 | 0.3% | Jun 23, 2026 | FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online s... |
| CVE-2025-71382 | HIGH | 7.1 | 0.3% | Jun 23, 2026 | MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows re... |
| CVE-2025-61029 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61024 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of... |
| CVE-2025-61028 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser... |
| CVE-2025-61027 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61025 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser... |
| CVE-2025-61023 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61022 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o... |
| CVE-2025-61021 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den... |
| CVE-2025-61020 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ... |
| CVE-2025-61019 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ... |
| CVE-2025-61018 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o... |
| CVE-2025-13162 | MEDIUM | 4.4 | 0.1% | Jun 23, 2026 | Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affect... |
| CVE-2025-62180 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authentica... |
| CVE-2025-55639 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomed... |
| CVE-2025-15619 | LOW | 3.5 | 0.1% | Jun 23, 2026 | HCL Connections contains a broken access control vulnerability that may allow an unauthorized user to view data in a sin... |
| CVE-2025-71376 | HIGH | 8.1 | 0.3% | Jun 23, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completion... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now