2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71370 | HIGH | 8.1 | 0.4% | Jun 23, 2026 | picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded ... |
| CVE-2025-71365 | HIGH | 8.1 | 0.3% | Jun 23, 2026 | picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function thro... |
| CVE-2025-71341 | HIGH | 8.1 | 0.5% | Jun 23, 2026 | picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attac... |
| CVE-2025-71337 | HIGH | 8.7 | 0.3% | Jun 23, 2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authen... |
| CVE-2025-71358 | HIGH | 8.1 | 0.2% | Jun 22, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entit... |
| CVE-2025-71344 | HIGH | 8.1 | 0.4% | Jun 22, 2026 | picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function... |
| CVE-2025-71339 | HIGH | 8.1 | 0.3% | Jun 22, 2026 | Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, a... |
| CVE-2025-66389 | HIGH | 7.5 | 0.4% | Jun 22, 2026 | GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler... |
| CVE-2025-33128 | MEDIUM | 5.4 | 0.1% | Jun 22, 2026 | IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerab... |
| CVE-2025-2669 | MEDIUM | 6.5 | 0.2% | Jun 22, 2026 | IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri... |
| CVE-2025-4994 | HIGH | 8.7 | 0.2% | Jun 22, 2026 | The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authenticatio... |
| CVE-2025-66336 | HIGH | 8.1 | 0.3% | Jun 22, 2026 | Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name... |
| CVE-2025-62198 | MEDIUM | 5.4 | 0.3% | Jun 22, 2026 | An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommend... |
| CVE-2025-71378 | HIGH | 7.8 | 0.3% | Jun 21, 2026 | picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attacker... |
| CVE-2025-71357 | HIGH | 7.8 | 0.2% | Jun 21, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in ... |
| CVE-2025-71351 | HIGH | 7.6 | 0.4% | Jun 21, 2026 | picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allow... |
| CVE-2025-71348 | HIGH | 7.8 | 0.4% | Jun 21, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config funct... |
| CVE-2025-71379 | HIGH | 7.5 | 0.2% | Jun 20, 2026 | vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Severa... |
| CVE-2025-71331 | MEDIUM | 6.1 | 0.2% | Jun 20, 2026 | Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat ... |
| CVE-2025-71326 | HIGH | 8.5 | 0.1% | Jun 19, 2026 | AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-pr... |
| CVE-2025-62821 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc... |
| CVE-2025-7737 | HIGH | 8.6 | 0.3% | Jun 19, 2026 | DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor... |
| CVE-2025-15661 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()... |
| CVE-2025-53114 | HIGH | 7.5 | 0.4% | Jun 18, 2026 | CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0... |
| CVE-2025-32437 | HIGH | 8.7 | 0.3% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now