2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-20389MEDIUM6.5In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and versions below 3.9.10, 3.8.58 and 3.7.28 of th...
CVE-2025-20388LOW2.7In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-20387MEDIUM6.5In Splunk Universal Forwarder for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an u...
CVE-2025-20386MEDIUM6.5In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to...
CVE-2025-20385MEDIUM4.8In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-20384MEDIUM5.3In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-20383MEDIUM4.3In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Sec...
CVE-2025-20382MEDIUM5.4In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507...
CVE-2025-20381MEDIUM5.4In Splunk MCP Server app versions below 0.2.4, a user with access to the "run_splunk_query" Model Context Protocol (MCP)...
CVE-2025-13751MEDIUM5.5Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a loc...
CVE-2025-13492HIGH7A potential security vulnerability has been identified in HP Image Assistant for versions prior to 5.3.3. The vulnerabil...
CVE-2025-7044MEDIUM6.5An Improper Input Validation vulnerability exists in the user websocket handler of MAAS. An authenticated, unprivileged ...
CVE-2025-65320HIGH7.5Abacre Restaurant Point of Sale (POS) up to 15.0.0.1656 are vulnerable to Cleartext Storage of Sensitive Information in ...
CVE-2025-57202MEDIUM6.1A stored cross-site scripting (XSS) vulnerability in the PwdGrp.cgi endpoint of AVTECH SECURITY Corporation DGM1104 Full...
CVE-2025-57201HIGH8.8AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec...
CVE-2025-57199HIGH8.8AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec...
CVE-2025-57198HIGH8.8AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec...
CVE-2025-55182CRITICAL10A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1...
CVE-2025-65267CRITICAL9In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to...
CVE-2025-57200MEDIUM6.5AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec...
CVE-2025-53841HIGH7.8The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50....
CVE-2025-13949MEDIUM6.3A vulnerability was identified in ProudMuBai GoFilm 1.0.0/1.0.1. Impacted is the function SingleUpload of the file /serv...
CVE-2025-13948MEDIUM5.6A vulnerability was determined in opsre go-ldap-admin up to 20251011. This issue affects some unknown processing of the ...
CVE-2025-13756MEDIUM4.3The Fluent Booking plugin for WordPress is vulnerable to unauthorized calendar import and management due to a missing ca...
CVE-2025-13401MEDIUM6.4The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the LCP Image to preload metabox i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now