2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71347HIGH8.1picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in red...
CVE-2025-71345HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd...
CVE-2025-71343HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_lab...
CVE-2025-71342HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A...
CVE-2025-71385MEDIUM6.1Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoi...
CVE-2025-69156HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
CVE-2025-69155HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
CVE-2025-69154HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
CVE-2025-69153HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
CVE-2025-69152HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.
CVE-2025-69134HIGH7.5Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
CVE-2025-69133HIGH7.5Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-69132MEDIUM6.5Subscriber Sensitive Data Exposure in Corpkit <= 1.0.5 versions.
CVE-2025-69094HIGH8.5Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
CVE-2025-66076MEDIUM5.3Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
CVE-2025-58902HIGH8.1Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
CVE-2025-23351CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-23350CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-15646CRITICAL9.8HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w...
CVE-2025-15666MEDIUM5.3A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerabili...
CVE-2025-71381MEDIUM6.9Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the midd...
CVE-2025-71374HIGH8.1picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met...
CVE-2025-71371HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce meth...
CVE-2025-71368HIGH8.1picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attacke...
CVE-2025-71363HIGH8.1picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to exe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now