2025 CVE Vulnerabilities

45,262 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20320HIGH7.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10...
CVE-2025-20319MEDIUM6.8In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-priv...
CVE-2025-20300MEDIUM4.3In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103...
CVE-2025-7137HIGH8.8A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This a...
CVE-2025-7136CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Online Recruitment Management System 1.0. Affe...
CVE-2025-53532MEDIUM5.3giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauth...
CVE-2025-53531HIGH7.5WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT...
CVE-2025-53530HIGH7.5WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT...
CVE-2025-53529CRITICAL9.8WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionar...
CVE-2025-53527CRITICAL9.8WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the...
CVE-2025-53526MEDIUM6.1WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php....
CVE-2025-53525MEDIUM6.1WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ...
CVE-2025-53497MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53491MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53377MEDIUM6.1WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ...
CVE-2025-36014MEDIUM6.7IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access ...
CVE-2025-1351HIGH7IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another use...
CVE-2025-7259MEDIUM6.5An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, whi...
CVE-2025-7135CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Online Recruitment Management System 1.0....
CVE-2025-7134CRITICAL9.8A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerabili...
CVE-2025-7057MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53487MEDIUM5.4The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are ins...
CVE-2025-53376HIGH8.8Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an...
CVE-2025-53375MEDIUM6.5Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an...
CVE-2025-53374MEDIUM4.3Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now