2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71324 | HIGH | 8.7 | 0.3% | Jun 25, 2026 | Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil... |
| CVE-2025-60465 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02... |
| CVE-2025-60464 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.... |
| CVE-2025-60473 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ... |
| CVE-2025-60466 | MEDIUM | 5 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0... |
| CVE-2025-8106 | — | — | — | Jun 24, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-60474 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo... |
| CVE-2025-60467 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ... |
| CVE-2025-60468 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflo... |
| CVE-2025-64719 | MEDIUM | 4.9 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a ... |
| CVE-2025-60471 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4B... |
| CVE-2025-71361 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem... |
| CVE-2025-71354 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun... |
| CVE-2025-71332 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation ... |
| CVE-2025-64105 | MEDIUM | 5.1 | 0.3% | Jun 23, 2026 | FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online s... |
| CVE-2025-71382 | HIGH | 7.1 | 0.3% | Jun 23, 2026 | MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows re... |
| CVE-2025-61029 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61024 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of... |
| CVE-2025-61028 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser... |
| CVE-2025-61027 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61025 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser... |
| CVE-2025-61023 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi... |
| CVE-2025-61022 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o... |
| CVE-2025-61021 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den... |
| CVE-2025-61020 | HIGH | 7.5 | 0.5% | Jun 23, 2026 | An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now