2025 CVE Vulnerabilities

45,181 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-7139MEDIUM5.4A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This iss...
CVE-2025-20325MEDIUM5.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1...
CVE-2025-20324MEDIUM5.4In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.10...
CVE-2025-20323MEDIUM4.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin...
CVE-2025-20322MEDIUM4.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1...
CVE-2025-20321MEDIUM4.3In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10...
CVE-2025-20319MEDIUM6.8In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-priv...
CVE-2025-20300MEDIUM4.3In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103...
CVE-2025-53532MEDIUM5.3giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauth...
CVE-2025-53526MEDIUM6.1WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php....
CVE-2025-53525MEDIUM6.1WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ...
CVE-2025-53497MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53491MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53377MEDIUM6.1WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ...
CVE-2025-36014MEDIUM6.7IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access ...
CVE-2025-7259MEDIUM6.5An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, whi...
CVE-2025-7057MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F...
CVE-2025-53487MEDIUM5.4The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are ins...
CVE-2025-53375MEDIUM6.5Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an...
CVE-2025-53374MEDIUM4.3Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an...
CVE-2025-7133MEDIUM5.4A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affec...
CVE-2025-6713MEDIUM6.5An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization d...
CVE-2025-6712MEDIUM6.5MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This c...
CVE-2025-6711MEDIUM4.9An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when cer...
CVE-2025-53486MEDIUM5.4The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly conca...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now