2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71331MEDIUM6.1Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat ...
CVE-2025-71326HIGH8.5AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-pr...
CVE-2025-62821CRITICAL9.1Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc...
CVE-2025-7737HIGH8.6DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor...
CVE-2025-15661MEDIUM6.5libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()...
CVE-2025-53114HIGH7.5CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0...
CVE-2025-32437HIGH8.7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2025-32436HIGH7.1AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2025-32424HIGH8.7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2025-32422HIGH8.7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2025-32392HIGH8.7AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent...
CVE-2025-58175HIGH8.2GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2...
CVE-2025-52465HIGH7.2GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2...
CVE-2025-27511HIGH7.2GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the G...
CVE-2025-10560CRITICAL9.3Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps ...
CVE-2025-71325CRITICAL9.8picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes...
CVE-2025-71323CRITICAL9.8picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoki...
CVE-2025-71322HIGH8.8PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypas...
CVE-2025-71321CRITICAL9.8picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous ...
CVE-2025-71320CRITICAL9.8picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller fun...
CVE-2025-32748MEDIUM6.1Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticate...
CVE-2025-26240HIGH8.4In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t...
CVE-2025-69189HIGH7.3Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Leve...
CVE-2025-69175HIGH8.1Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions.
CVE-2025-69174HIGH8.1Unauthenticated Local File Inclusion in Etude <= 1.6 versions.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now