2025 CVE Vulnerabilities
45,262 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20320 | HIGH | 7.3 | 0.4% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10... |
| CVE-2025-20319 | MEDIUM | 6.8 | 0.4% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-priv... |
| CVE-2025-20300 | MEDIUM | 4.3 | 0.3% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103... |
| CVE-2025-7137 | HIGH | 8.8 | 0.4% | Jul 7, 2025 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been classified as critical. This a... |
| CVE-2025-7136 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability, which was classified as critical, was found in Campcodes Online Recruitment Management System 1.0. Affe... |
| CVE-2025-53532 | MEDIUM | 5.3 | 0.3% | Jul 7, 2025 | giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauth... |
| CVE-2025-53531 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT... |
| CVE-2025-53530 | HIGH | 7.5 | 0.4% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HT... |
| CVE-2025-53529 | CRITICAL | 9.8 | 0.5% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionar... |
| CVE-2025-53527 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the... |
| CVE-2025-53526 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php.... |
| CVE-2025-53525 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-53497 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53491 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53377 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-36014 | MEDIUM | 6.7 | 0.2% | Jul 7, 2025 | IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access ... |
| CVE-2025-1351 | HIGH | 7 | 0.1% | Jul 7, 2025 | IBM Storage Virtualize 8.5, 8.6, and 8.7 products could allow a user to escalate their privileges to that of another use... |
| CVE-2025-7259 | MEDIUM | 6.5 | 0.3% | Jul 7, 2025 | An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, whi... |
| CVE-2025-7135 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability, which was classified as critical, has been found in Campcodes Online Recruitment Management System 1.0.... |
| CVE-2025-7134 | CRITICAL | 9.8 | 0.4% | Jul 7, 2025 | A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1.0. This vulnerabili... |
| CVE-2025-7057 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53487 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are ins... |
| CVE-2025-53376 | HIGH | 8.8 | 1.1% | Jul 7, 2025 | Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an... |
| CVE-2025-53375 | MEDIUM | 6.5 | 0.4% | Jul 7, 2025 | Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an... |
| CVE-2025-53374 | MEDIUM | 4.3 | 0.2% | Jul 7, 2025 | Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now