2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71373 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to byp... |
| CVE-2025-71372 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all... |
| CVE-2025-71369 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basich... |
| CVE-2025-71367 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to b... |
| CVE-2025-71366 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle... |
| CVE-2025-71364 | HIGH | 8.1 | 0.6% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle redu... |
| CVE-2025-71362 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbi... |
| CVE-2025-71360 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce meth... |
| CVE-2025-71359 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in t... |
| CVE-2025-71356 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expres... |
| CVE-2025-71353 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get funct... |
| CVE-2025-71347 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in red... |
| CVE-2025-71345 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd... |
| CVE-2025-71343 | HIGH | 8.1 | 0.3% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_lab... |
| CVE-2025-71342 | HIGH | 8.1 | 0.4% | Jul 4, 2026 | picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A... |
| CVE-2025-69156 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions. |
| CVE-2025-69155 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions. |
| CVE-2025-69154 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions. |
| CVE-2025-69153 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions. |
| CVE-2025-69152 | HIGH | 7.1 | — | Jul 2, 2026 | Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions. |
| CVE-2025-69134 | HIGH | 7.5 | — | Jul 2, 2026 | Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions. |
| CVE-2025-69133 | HIGH | 7.5 | — | Jul 2, 2026 | Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions. |
| CVE-2025-69094 | HIGH | 8.5 | — | Jul 2, 2026 | Subscriber SQL Injection in Unicamp <= 2.2.2 versions. |
| CVE-2025-58902 | HIGH | 8.1 | — | Jul 2, 2026 | Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions. |
| CVE-2025-71374 | HIGH | 8.1 | 0.6% | Jun 30, 2026 | picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now