2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71371 | HIGH | 8.1 | 0.5% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth... |
| CVE-2025-71368 | HIGH | 8.1 | 0.8% | Jun 30, 2026 | picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke... |
| CVE-2025-71363 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe... |
| CVE-2025-71355 | HIGH | 7.6 | 0.6% | Jun 30, 2026 | Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat... |
| CVE-2025-71352 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce... |
| CVE-2025-71350 | HIGH | 8.1 | 0.4% | Jun 30, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met... |
| CVE-2025-71349 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att... |
| CVE-2025-7406 | HIGH | 7.8 | 0.1% | Jun 30, 2026 | Nokia MantaRay NM is vulnerable to a sudo privilege escalation vulnerability where a local attacker possessing administr... |
| CVE-2025-24815 | HIGH | 7.8 | 0.2% | Jun 30, 2026 | Nokia MantaRay NM is subject to an unrestricted file upload vulnerability due to insufficient file type validation. Succ... |
| CVE-2025-2902 | HIGH | 8.3 | 0.2% | Jun 29, 2026 | Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform. This issue affects Hit... |
| CVE-2025-68064 | HIGH | 7.5 | — | Jun 26, 2026 | Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. |
| CVE-2025-68063 | HIGH | 7.5 | — | Jun 26, 2026 | Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versio... |
| CVE-2025-68052 | HIGH | 8.8 | — | Jun 26, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions. |
| CVE-2025-7958 | HIGH | 7.1 | — | Jun 26, 2026 | A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can exe... |
| CVE-2025-71340 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode... |
| CVE-2025-71335 | HIGH | 8.6 | 0.3% | Jun 25, 2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens aft... |
| CVE-2025-71328 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their accou... |
| CVE-2025-71324 | HIGH | 8.7 | 0.3% | Jun 25, 2026 | Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-fil... |
| CVE-2025-60464 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.... |
| CVE-2025-60474 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allo... |
| CVE-2025-60467 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box ... |
| CVE-2025-71361 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing rem... |
| CVE-2025-71354 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText fun... |
| CVE-2025-71332 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation ... |
| CVE-2025-71382 | HIGH | 7.1 | 0.3% | Jun 23, 2026 | MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows re... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now