2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71371HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth...
CVE-2025-71368HIGH8.1picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke...
CVE-2025-71363HIGH8.1picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe...
CVE-2025-71355HIGH7.6Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat...
CVE-2025-71352HIGH8.1picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce...
CVE-2025-71350HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met...
CVE-2025-71349HIGH8.1picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att...
CVE-2025-7406HIGH7.8Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administr...
CVE-2025-24815HIGH7.8Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Succ...
CVE-2025-2902HIGH8.3Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hit...
CVE-2025-68064HIGH7.5Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
CVE-2025-68063HIGH7.5Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versio...
CVE-2025-68052HIGH8.8Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
CVE-2025-7958HIGH7.1A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe...
CVE-2025-71340HIGH8.1picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode...
CVE-2025-71335HIGH8.6Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens aft...
CVE-2025-71328HIGH8.8Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their accou...
CVE-2025-71324HIGH8.7Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil...
CVE-2025-60464HIGH7.8A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26....
CVE-2025-60474HIGH7.5A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo...
CVE-2025-60467HIGH7.5A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ...
CVE-2025-71361HIGH8.1picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem...
CVE-2025-71354HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun...
CVE-2025-71332HIGH8.8Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation ...
CVE-2025-71382HIGH7.1MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows re...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now