2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11919 | CRITICAL | 9.6 | — | Jun 26, 2026 | The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the... |
| CVE-2025-64152 | CRITICAL | 9.1 | — | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu... |
| CVE-2025-55017 | CRITICAL | 9.1 | — | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu... |
| CVE-2025-71338 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauth... |
| CVE-2025-71336 | CRITICAL | 9.8 | 0.7% | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera... |
| CVE-2025-71334 | CRITICAL | 9.8 | 0.9% | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin... |
| CVE-2025-71333 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin... |
| CVE-2025-71327 | CRITICAL | 9.3 | 0.5% | Jun 25, 2026 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows... |
| CVE-2025-62821 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc... |
| CVE-2025-10560 | CRITICAL | 9.3 | 0.4% | Jun 18, 2026 | Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps ... |
| CVE-2025-71325 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes... |
| CVE-2025-71323 | CRITICAL | 9.8 | 0.8% | Jun 17, 2026 | picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoki... |
| CVE-2025-71321 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous ... |
| CVE-2025-71320 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller fun... |
| CVE-2025-69127 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. |
| CVE-2025-69111 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. |
| CVE-2025-60236 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: f... |
| CVE-2025-60231 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue aff... |
| CVE-2025-60230 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects... |
| CVE-2025-60229 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: fr... |
| CVE-2025-59554 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. |
| CVE-2025-69179 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. |
| CVE-2025-69129 | CRITICAL | 10 | 0.4% | Jun 17, 2026 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 vers... |
| CVE-2025-69122 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. |
| CVE-2025-69108 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now