2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71324HIGH8.7Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil...
CVE-2025-60465MEDIUM6.1A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02...
CVE-2025-60464HIGH7.8A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26....
CVE-2025-60473MEDIUM5.5A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ...
CVE-2025-60466MEDIUM5A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.0...
CVE-2025-8106——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-60474HIGH7.5A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo...
CVE-2025-60467HIGH7.5A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ...
CVE-2025-60468MEDIUM5.5GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflo...
CVE-2025-64719MEDIUM4.9Gogs is an open source self-hosted Git service. Prior to 0.14.3, a malicious user with rights to create a new file on a ...
CVE-2025-60471MEDIUM5.5A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4B...
CVE-2025-71361HIGH8.1picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem...
CVE-2025-71354HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun...
CVE-2025-71332HIGH8.8Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation ...
CVE-2025-64105MEDIUM5.1FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online s...
CVE-2025-71382HIGH7.1MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows re...
CVE-2025-61029HIGH7.5An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi...
CVE-2025-61024HIGH7.5An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of...
CVE-2025-61028HIGH7.5An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser...
CVE-2025-61027HIGH7.5An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi...
CVE-2025-61025HIGH7.5An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser...
CVE-2025-61023HIGH7.5An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi...
CVE-2025-61022HIGH7.5An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o...
CVE-2025-61021HIGH7.5An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den...
CVE-2025-61020HIGH7.5An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now