2025 CVE Vulnerabilities

45,262 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-7147CRITICAL9.8A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by...
CVE-2025-7144MEDIUM4.8A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu...
CVE-2025-7143MEDIUM5.4A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This...
CVE-2025-7142MEDIUM5.4A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0....
CVE-2025-53543MEDIUM4.2Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored ...
CVE-2025-53540HIGH8.7arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Se...
CVE-2025-53539HIGH7.5FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr...
CVE-2025-53496MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-7141MEDIUM5.4A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this...
CVE-2025-7140MEDIUM5.4A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is...
CVE-2025-6044MEDIUM6.1An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the gara...
CVE-2025-53499CRITICAL9.1Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access...
CVE-2025-53498MEDIUM5.3Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks...
CVE-2025-53495CRITICAL9.1Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access...
CVE-2025-53488MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53478MEDIUM5.4The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certa...
CVE-2025-7139MEDIUM5.4A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This iss...
CVE-2025-7138HIGH8.8A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vul...
CVE-2025-53536HIGH8.1Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker...
CVE-2025-53535LOW2.1Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the origin...
CVE-2025-20325MEDIUM5.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1...
CVE-2025-20324MEDIUM5.4In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.10...
CVE-2025-20323MEDIUM4.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin...
CVE-2025-20322MEDIUM4.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1...
CVE-2025-20321MEDIUM4.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now