2025 CVE Vulnerabilities
45,262 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7147 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | A vulnerability has been found in CodeAstro Patient Record Management System 1.0 and classified as critical. Affected by... |
| CVE-2025-7144 | MEDIUM | 4.8 | 0.3% | Jul 7, 2025 | A vulnerability has been found in SourceCodester Best Salon Management System 1.0 and classified as problematic. This vu... |
| CVE-2025-7143 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability, which was classified as problematic, was found in SourceCodester Best Salon Management System 1.0. This... |
| CVE-2025-7142 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability, which was classified as problematic, has been found in SourceCodester Best Salon Management System 1.0.... |
| CVE-2025-53543 | MEDIUM | 4.2 | 0.2% | Jul 7, 2025 | Kestra is an event-driven orchestration platform. The error message in execution "Overview" tab is vulnerable to stored ... |
| CVE-2025-53540 | HIGH | 8.7 | 0.3% | Jul 7, 2025 | arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Se... |
| CVE-2025-53539 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetr... |
| CVE-2025-53496 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-7141 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability classified as problematic was found in SourceCodester Best Salon Management System 1.0. Affected by this... |
| CVE-2025-7140 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability classified as problematic has been found in SourceCodester Best Salon Management System 1.0. Affected is... |
| CVE-2025-6044 | MEDIUM | 6.1 | 0.1% | Jul 7, 2025 | An Improper Access Control vulnerability in the Stylus Tools component of Google ChromeOS version 16238.64.0 on the gara... |
| CVE-2025-53499 | CRITICAL | 9.1 | 0.3% | Jul 7, 2025 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access... |
| CVE-2025-53498 | MEDIUM | 5.3 | 0.2% | Jul 7, 2025 | Insufficient Logging vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Data Leakage Attacks... |
| CVE-2025-53495 | CRITICAL | 9.1 | 0.3% | Jul 7, 2025 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - AbuseFilter Extension allows Unauthorized Access... |
| CVE-2025-53488 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53478 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | The CheckUser extension’s Special:Investigate interface is vulnerable to reflected XSS due to improper escaping of certa... |
| CVE-2025-7139 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This iss... |
| CVE-2025-7138 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been declared as critical. This vul... |
| CVE-2025-53536 | HIGH | 8.1 | 0.7% | Jul 7, 2025 | Roo Code is an AI-powered autonomous coding agent. Prior to 3.22.6, if the victim had "Write" auto-approved, an attacker... |
| CVE-2025-53535 | LOW | 2.1 | 0.3% | Jul 7, 2025 | Better Auth is an authentication and authorization library for TypeScript. An open redirect has been found in the origin... |
| CVE-2025-20325 | MEDIUM | 5.3 | 0.3% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1... |
| CVE-2025-20324 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.10... |
| CVE-2025-20323 | MEDIUM | 4.3 | 0.3% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin... |
| CVE-2025-20322 | MEDIUM | 4.3 | 0.2% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1... |
| CVE-2025-20321 | MEDIUM | 4.3 | 0.2% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now