Weekly digest
Week 15, 2025 (7–13 Apr)
A quiet week: only 15 new CVEs against a recent average of about 53. Of those, 1 critical and 2 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. picklescan was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2025-3248Critical· 9.8CISA KEVPoCLangflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
CVE-2025-30473High· 8.8Apache Airflow Common SQL Provider Vulnerable to SQL Injection
Apache Airflow Common SQL Provider Vulnerable to SQL Injection
CVE-2025-46417HighPicklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
Picklescan Vulnerable to Exfiltration via DNS via linecache and ssl.get_server_certificate
CVE-2025-32387Medium· 6.5Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
Helm Allows A Specially Crafted JSON Schema To Cause A Stack Overflow
CVE-2025-32386Medium· 6.5Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
Helm Allows A Specially Crafted Chart Archive To Cause Out Of Memory Termination
CVE-2025-32381Medium· 6.5xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
xgrammar Vulnerable to Denial of Service (DoS) by abusing unbounded cache in memory
CVE-2024-52980Medium· 6.5Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
Elasticsearch-grok Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2025-2251Medium· 6.2A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism
A security flaw exists in WildFly and JBoss Enterprise Application Platform (EAP) within the Enterprise JavaBeans (EJB) remote invocation mechanism. This vulnerability stems from untrusted data deserialization handled by JBoss Marshallin…
CVE-2025-22015Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migration A shmem folio can be either in page cache or in swap cache, but not at the same time
In the Linux kernel, the following vulnerability has been resolved: mm/migrate: fix shmem xarray update during migration A shmem folio can be either in page cache or in swap cache, but not at the same time. Namely, once it is in swap …
CVE-2025-1386MediumCVE-2025-1386- Query smuggling in ch-go library
CVE-2025-1386- Query smuggling in ch-go library
CVE-2025-71355MediumPicklescan failed to detect to some unsafe global function in Numpy library
Picklescan failed to detect to some unsafe global function in Numpy library
CVE-2025-71351MediumPicklescan missing detection when calling built-in python library function timeit.timeit()
Picklescan missing detection when calling built-in python library function timeit.timeit()
Most-affected vendors
By CVEs published in the period.