2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-69154HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
CVE-2025-69153HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
CVE-2025-69152HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.
CVE-2025-69134HIGH7.5Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
CVE-2025-69133HIGH7.5Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-69132MEDIUM6.5Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
CVE-2025-69094HIGH8.5Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
CVE-2025-66076MEDIUM5.3Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
CVE-2025-58902HIGH8.1Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
CVE-2025-23351CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-23350CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-15646CRITICAL9.8HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w...
CVE-2025-15666MEDIUM5.3A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili...
CVE-2025-71381MEDIUM6.9Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the midd...
CVE-2025-71374HIGH8.1picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met...
CVE-2025-71371HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth...
CVE-2025-71368HIGH8.1picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke...
CVE-2025-71363HIGH8.1picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe...
CVE-2025-71355HIGH7.6Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass stat...
CVE-2025-71352HIGH8.1picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce...
CVE-2025-71350HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce met...
CVE-2025-71349HIGH8.1picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing att...
CVE-2025-36359MEDIUM6.5IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow...
CVE-2025-36336MEDIUM5.9IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to ob...
CVE-2025-36333MEDIUM4.3IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to perform unauthorized actio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now