2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-11919CRITICAL9.6The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the...
CVE-2025-64152CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2025-55017CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2025-71338CRITICAL9.8Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauth...
CVE-2025-71336CRITICAL9.8Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera...
CVE-2025-71334CRITICAL9.8Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin...
CVE-2025-71333CRITICAL9.8Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin...
CVE-2025-71327CRITICAL9.3Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows...
CVE-2025-62821CRITICAL9.1Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc...
CVE-2025-10560CRITICAL9.3Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps ...
CVE-2025-71325CRITICAL9.8picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes...
CVE-2025-71323CRITICAL9.8picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoki...
CVE-2025-71321CRITICAL9.8picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous ...
CVE-2025-71320CRITICAL9.8picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller fun...
CVE-2025-69127CRITICAL9.8Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions.
CVE-2025-69111CRITICAL9.8Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions.
CVE-2025-60236CRITICAL9.8Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: f...
CVE-2025-60231CRITICAL9.8Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue aff...
CVE-2025-60230CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects...
CVE-2025-60229CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: fr...
CVE-2025-59554CRITICAL9.3Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions.
CVE-2025-69179CRITICAL9.8Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions.
CVE-2025-69129CRITICAL10Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 vers...
CVE-2025-69122CRITICAL9.8Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions.
CVE-2025-69108CRITICAL9.8Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now