2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71334 | CRITICAL | 9.8 | 0.9% | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missin... |
| CVE-2025-71333 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoin... |
| CVE-2025-71327 | CRITICAL | 9.3 | 0.5% | Jun 25, 2026 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows... |
| CVE-2025-62821 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc... |
| CVE-2025-10560 | CRITICAL | 9.3 | 0.4% | Jun 18, 2026 | Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps ... |
| CVE-2025-71325 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes... |
| CVE-2025-71323 | CRITICAL | 9.8 | 0.8% | Jun 17, 2026 | picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoki... |
| CVE-2025-71321 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous ... |
| CVE-2025-71320 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller fun... |
| CVE-2025-69127 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. |
| CVE-2025-69111 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. |
| CVE-2025-60236 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: f... |
| CVE-2025-60231 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue aff... |
| CVE-2025-60230 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects... |
| CVE-2025-60229 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: fr... |
| CVE-2025-59554 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. |
| CVE-2025-69179 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Ticket Management System <= 1.9 versions. |
| CVE-2025-69129 | CRITICAL | 10 | 0.4% | Jun 17, 2026 | Unauthenticated Arbitrary File Upload in WordPress & WooCommerce Scraper Plugin, Import Data from Any Site <= 1.0.7 vers... |
| CVE-2025-69122 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in SeaFood Company <= 1.4 versions. |
| CVE-2025-69108 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hot Coffee <= 1.7 versions. |
| CVE-2025-60218 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in PT Luxa Addons <= 1.2.2 versions. |
| CVE-2025-60205 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in ThemeREX Addons <= 2.36.1.1 versions. |
| CVE-2025-59872 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability, If the server is configured to execute code, t... |
| CVE-2025-13036 | CRITICAL | 9.2 | 0.3% | Jun 16, 2026 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending request... |
| CVE-2025-6254 | CRITICAL | 9.8 | 0.5% | Jun 10, 2026 | The Doctreat Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.6.8... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now