2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69154 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions. |
| CVE-2025-69153 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions. |
| CVE-2025-69152 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. |
| CVE-2025-69134 | HIGH | 7.5 | — | Jul 2, 2026 | Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. |
| CVE-2025-69133 | HIGH | 7.5 | — | Jul 2, 2026 | Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. |
| CVE-2025-69132 | MEDIUM | 6.5 | — | Jul 2, 2026 | Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions. |
| CVE-2025-69094 | HIGH | 8.5 | — | Jul 2, 2026 | Subscriber SQL Injection in Unicamp <= 2.2.2 versions. |
| CVE-2025-66076 | MEDIUM | 5.3 | — | Jul 2, 2026 | Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions. |
| CVE-2025-58902 | HIGH | 8.1 | — | Jul 2, 2026 | Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. |
| CVE-2025-23351 | CRITICAL | 9 | — | Jul 1, 2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ... |
| CVE-2025-23350 | CRITICAL | 9 | — | Jul 1, 2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ... |
| CVE-2025-15646 | CRITICAL | 9.8 | 0.7% | Jul 1, 2026 | HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w... |
| CVE-2025-15666 | MEDIUM | 5.3 | 0.1% | Jul 1, 2026 | A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili... |
| CVE-2025-71381 | MEDIUM | 6.9 | 0.3% | Jun 30, 2026 | Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the midd... |
| CVE-2025-71374 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met... |
| CVE-2025-71371 | HIGH | 8.1 | 0.5% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth... |
| CVE-2025-71368 | HIGH | 8.1 | 0.8% | Jun 30, 2026 | picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke... |
| CVE-2025-71363 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe... |
| CVE-2025-71355 | HIGH | 7.6 | 0.6% | Jun 30, 2026 | Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat... |
| CVE-2025-71352 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce... |
| CVE-2025-71350 | HIGH | 8.1 | 0.4% | Jun 30, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met... |
| CVE-2025-71349 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att... |
| CVE-2025-36359 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow... |
| CVE-2025-36336 | MEDIUM | 5.9 | 0.2% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to ob... |
| CVE-2025-36333 | MEDIUM | 4.3 | 0.3% | Jun 30, 2026 | IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now