2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71370HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded ...
CVE-2025-71365HIGH8.1picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function thro...
CVE-2025-71341HIGH8.1picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attac...
CVE-2025-71337HIGH8.7Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authen...
CVE-2025-71358HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entit...
CVE-2025-71344HIGH8.1picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function...
CVE-2025-71339HIGH8.1Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, a...
CVE-2025-66389HIGH7.5GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler...
CVE-2025-33128MEDIUM5.4IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerab...
CVE-2025-2669MEDIUM6.5IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a pri...
CVE-2025-4994HIGH8.7The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authenticatio...
CVE-2025-66336HIGH8.1Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name...
CVE-2025-62198MEDIUM5.4An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommend...
CVE-2025-71378HIGH7.8picklescan before 0.0.30 fails to detect cProfile.runctx function calls in pickle file reduce methods, allowing attacker...
CVE-2025-71357HIGH7.8picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.pyshell.ModifiedInterpreter.runcommand in ...
CVE-2025-71351HIGH7.6picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allow...
CVE-2025-71348HIGH7.8picklescan before 0.0.28 fails to detect malicious pickle files that invoke torch.utils._config_module.load_config funct...
CVE-2025-71379HIGH7.5vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Severa...
CVE-2025-71331MEDIUM6.1Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat ...
CVE-2025-71326HIGH8.5AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-pr...
CVE-2025-62821CRITICAL9.1Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc...
CVE-2025-7737HIGH8.6DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor...
CVE-2025-15661MEDIUM6.5libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()...
CVE-2025-53114HIGH7.5CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0...
CVE-2025-32437HIGH8.7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now