2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71373HIGH8.1picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to byp...
CVE-2025-71372HIGH8.1Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all...
CVE-2025-71369HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basich...
CVE-2025-71367HIGH8.1picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to b...
CVE-2025-71366HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle...
CVE-2025-71364HIGH8.1picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle redu...
CVE-2025-71362HIGH8.1picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbi...
CVE-2025-71360HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce meth...
CVE-2025-71359HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in t...
CVE-2025-71356HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expres...
CVE-2025-71353HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get funct...
CVE-2025-71347HIGH8.1picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in red...
CVE-2025-71345HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd...
CVE-2025-71343HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_lab...
CVE-2025-71342HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A...
CVE-2025-69156HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
CVE-2025-69155HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
CVE-2025-69154HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
CVE-2025-69153HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
CVE-2025-69152HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.
CVE-2025-69134HIGH7.5Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
CVE-2025-69133HIGH7.5Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-69094HIGH8.5Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
CVE-2025-58902HIGH8.1Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
CVE-2025-71374HIGH8.1picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce met...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now