2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71375HIGH8.1picklescan before 0.0.34 fails to detect the _operator.methodcaller built-in function when scanning pickle files for mal...
CVE-2025-71373HIGH8.1picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to byp...
CVE-2025-71372HIGH8.1Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran.getlincoef gadget in pickle __reduce__ methods, all...
CVE-2025-71369HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basich...
CVE-2025-71367HIGH8.1picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to b...
CVE-2025-71366HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.utils.bottleneck.__main__.run_cprofile function calls in pickle...
CVE-2025-71364HIGH8.1picklescan before 0.0.30 fails to detect the asyncio.unix_events._UnixSubprocessTransport._start function in pickle redu...
CVE-2025-71362HIGH8.1picklescan before 0.0.33 fails to detect unsafe deserialization when numpy.f2py.crackfortran functions call eval on arbi...
CVE-2025-71360HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.calltip.get_entity function in reduce meth...
CVE-2025-71359HIGH8.1picklescan before 0.0.29 fails to detect malicious pickle payloads that utilize lib2to3.pgen2.grammar.Grammar.loads in t...
CVE-2025-71356HIGH8.1picklescan before 0.0.28 fails to detect malicious torch.fx.experimental.symbolic_shapes.ShapeEnv.evaluate_guards_expres...
CVE-2025-71353HIGH8.1picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get funct...
CVE-2025-71347HIGH8.1picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in red...
CVE-2025-71345HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd...
CVE-2025-71343HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_lab...
CVE-2025-71342HIGH8.1picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. A...
CVE-2025-69156HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
CVE-2025-69155HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
CVE-2025-69154HIGH7.1Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
CVE-2025-69153HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
CVE-2025-69152HIGH7.1Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versions.
CVE-2025-69134HIGH7.5Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
CVE-2025-69133HIGH7.5Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
CVE-2025-69094HIGH8.5Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
CVE-2025-58902HIGH8.1Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now