2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20389 | MEDIUM | 6.5 | 0.4% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of th... |
| CVE-2025-20388 | LOW | 2.7 | 0.3% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-20387 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an u... |
| CVE-2025-20386 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to... |
| CVE-2025-20385 | MEDIUM | 4.8 | 0.2% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-20384 | MEDIUM | 5.3 | 0.3% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-20383 | MEDIUM | 4.3 | 0.3% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Sec... |
| CVE-2025-20382 | MEDIUM | 5.4 | 0.2% | Dec 3, 2025 | In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507... |
| CVE-2025-20381 | MEDIUM | 5.4 | 0.2% | Dec 3, 2025 | In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP)... |
| CVE-2025-13751 | MEDIUM | 5.5 | 0.2% | Dec 3, 2025 | Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a loc... |
| CVE-2025-13492 | HIGH | 7 | 0.1% | Dec 3, 2025 | A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerabil... |
| CVE-2025-7044 | MEDIUM | 6.5 | 0.2% | Dec 3, 2025 | An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged ... |
| CVE-2025-65320 | HIGH | 7.5 | 0.2% | Dec 3, 2025 | Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in ... |
| CVE-2025-57202 | MEDIUM | 6.1 | 0.4% | Dec 3, 2025 | A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 Full... |
| CVE-2025-57201 | HIGH | 8.8 | 12.8% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-57199 | HIGH | 8.8 | 2.6% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-57198 | HIGH | 8.8 | 2.1% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-55182 | CRITICAL | 10 | 99.6% | Dec 3, 2025 | A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1... |
| CVE-2025-65267 | CRITICAL | 9 | 0.3% | Dec 3, 2025 | In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to... |
| CVE-2025-57200 | MEDIUM | 6.5 | 1.8% | Dec 3, 2025 | AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec... |
| CVE-2025-53841 | HIGH | 7.8 | 0.1% | Dec 3, 2025 | The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.... |
| CVE-2025-13949 | MEDIUM | 6.3 | 0.2% | Dec 3, 2025 | A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /serv... |
| CVE-2025-13948 | MEDIUM | 5.6 | 0.3% | Dec 3, 2025 | A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the ... |
| CVE-2025-13756 | MEDIUM | 4.3 | 0.2% | Dec 3, 2025 | The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing ca... |
| CVE-2025-13401 | MEDIUM | 6.4 | 0.3% | Dec 3, 2025 | The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now