2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7139 | MEDIUM | 5.4 | 0.3% | Jul 7, 2025 | A vulnerability was found in SourceCodester Best Salon Management System 1.0. It has been rated as problematic. This iss... |
| CVE-2025-20325 | MEDIUM | 5.3 | 0.3% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1... |
| CVE-2025-20324 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.7, and 9.1.10 and Splunk Cloud Platform versions below 9.3.2411.10... |
| CVE-2025-20323 | MEDIUM | 4.3 | 0.3% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin... |
| CVE-2025-20322 | MEDIUM | 4.3 | 0.2% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.1... |
| CVE-2025-20321 | MEDIUM | 4.3 | 0.2% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7 and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.10... |
| CVE-2025-20319 | MEDIUM | 6.8 | 0.4% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-priv... |
| CVE-2025-20300 | MEDIUM | 4.3 | 0.3% | Jul 7, 2025 | In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103... |
| CVE-2025-53532 | MEDIUM | 5.3 | 0.3% | Jul 7, 2025 | giscus is a commenting system powered by GitHub Discussions. A bug in giscus' discussions creation API allowed an unauth... |
| CVE-2025-53526 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php.... |
| CVE-2025-53525 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-53497 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53491 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53377 | MEDIUM | 6.1 | 0.2% | Jul 7, 2025 | WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified ... |
| CVE-2025-36014 | MEDIUM | 6.7 | 0.2% | Jul 7, 2025 | IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access ... |
| CVE-2025-7259 | MEDIUM | 6.5 | 0.3% | Jul 7, 2025 | An authorized user can issue queries with duplicate _id fields, that leads to unexpected behavior in MongoDB Server, whi... |
| CVE-2025-7057 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-53487 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | The ApprovedRevs extension for MediaWiki is vulnerable to stored XSS in multiple locations where system messages are ins... |
| CVE-2025-53375 | MEDIUM | 6.5 | 0.4% | Jul 7, 2025 | Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an... |
| CVE-2025-53374 | MEDIUM | 4.3 | 0.2% | Jul 7, 2025 | Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an... |
| CVE-2025-7133 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | A vulnerability classified as problematic has been found in CodeAstro Online Movie Ticket Booking System 1.0. This affec... |
| CVE-2025-6713 | MEDIUM | 6.5 | 0.3% | Jul 7, 2025 | An unauthorized user may leverage a specially crafted aggregation pipeline to access data without proper authorization d... |
| CVE-2025-6712 | MEDIUM | 6.5 | 0.3% | Jul 7, 2025 | MongoDB Server may be susceptible to disruption caused by high memory usage, potentially leading to server crash. This c... |
| CVE-2025-6711 | MEDIUM | 4.9 | 0.2% | Jul 7, 2025 | An issue has been identified in MongoDB Server where unredacted queries may inadvertently appear in server logs when cer... |
| CVE-2025-53486 | MEDIUM | 5.4 | 0.2% | Jul 7, 2025 | The WikiCategoryTagCloud extension is vulnerable to reflected XSS via the linkstyle attribute, which is improperly conca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now