2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-59617HIGH7.3Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input.
CVE-2025-59616HIGH7.8Memory Corruption when processing multiple IOCTL calls with the same buffer file descriptor input due to accessing alrea...
CVE-2025-59615HIGH7.8Memory Corruption when invoking device input/output control operations for mapping and unmapping persistent memory buffe...
CVE-2025-53831HIGH8.2DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application o...
CVE-2025-53830CRITICAL9.1Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud...
CVE-2025-53829HIGH8ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attack...
CVE-2025-53828HIGH8.5SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli...
CVE-2025-53827CRITICAL9.1ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi...
CVE-2025-15668LOW3.3A vulnerability was identified in GPAC up to b40ce70f5. This issue affects the function sgpd_del_entry of the file src/i...
CVE-2025-15667LOW3.3A vulnerability was determined in GPAC up to 2.5-DEV. This vulnerability affects the function gf_isom_nalu_sample_rewrit...
CVE-2025-8591MEDIUM6.1The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back ...
CVE-2025-13475HIGH7.3In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes be...
CVE-2025-71380HIGH8.8The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n ru...
CVE-2025-71375HIGH8.1picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for mal...
CVE-2025-71373HIGH8.1picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to byp...
CVE-2025-71372HIGH8.1Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all...
CVE-2025-71369HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basich...
CVE-2025-71367HIGH8.1picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to b...
CVE-2025-71366HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle...
CVE-2025-71364HIGH8.1picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle redu...
CVE-2025-71362HIGH8.1picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbi...
CVE-2025-71360HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce meth...
CVE-2025-71359HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in t...
CVE-2025-71356HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expres...
CVE-2025-71353HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get funct...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now