2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71331 | MEDIUM | 6.1 | 0.2% | Jun 20, 2026 | Flowise before 3.0.8 contains a cross-site scripting (XSS) vulnerability caused by insufficient input filtering in chat ... |
| CVE-2025-71326 | HIGH | 8.5 | 0.1% | Jun 19, 2026 | AVAST Antivirus 25.11 contains an unquoted service path vulnerability in the SecureLine service that allows local non-pr... |
| CVE-2025-62821 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return suc... |
| CVE-2025-7737 | HIGH | 8.6 | 0.3% | Jun 19, 2026 | DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Stor... |
| CVE-2025-15661 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink()... |
| CVE-2025-53114 | HIGH | 7.5 | 0.4% | Jun 18, 2026 | CometD is a scalable comet implementation for web messaging. In versions 5.0.0 through 5.0.22, 6.0.0 through 6.0.18, 7.0... |
| CVE-2025-32437 | HIGH | 8.7 | 0.3% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-32436 | HIGH | 7.1 | 0.2% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-32424 | HIGH | 8.7 | 0.3% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-32422 | HIGH | 8.7 | 0.3% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-32392 | HIGH | 8.7 | 0.3% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2025-58175 | HIGH | 8.2 | 0.3% | Jun 18, 2026 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2... |
| CVE-2025-52465 | HIGH | 7.2 | 0.4% | Jun 18, 2026 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.2... |
| CVE-2025-27511 | HIGH | 7.2 | 0.6% | Jun 18, 2026 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the G... |
| CVE-2025-10560 | CRITICAL | 9.3 | 0.4% | Jun 18, 2026 | Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret material in the Worksnaps ... |
| CVE-2025-71325 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | picklescan before 0.0.27 contains a parsing logic error in the _list_globals function when handling STACK_GLOBAL opcodes... |
| CVE-2025-71323 | CRITICAL | 9.8 | 0.8% | Jun 17, 2026 | picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoki... |
| CVE-2025-71322 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | PickleScan before 0.0.33 fails to include the pty.spawn function in its unsafe globals list, allowing attackers to bypas... |
| CVE-2025-71321 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an arbitrary file writing vulnerability that allows attackers to bypass the dangerous ... |
| CVE-2025-71320 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller fun... |
| CVE-2025-32748 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticate... |
| CVE-2025-26240 | HIGH | 8.4 | 0.4% | Jun 17, 2026 | In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of t... |
| CVE-2025-69189 | HIGH | 7.3 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in EMV JobBank allows Exploiting Incorrectly Configured Access Control Security Leve... |
| CVE-2025-69175 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Line Agency <= 1.3.1 versions. |
| CVE-2025-69174 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Etude <= 1.6 versions. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now