2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-67282MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileg...
CVE-2025-67281MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and ...
CVE-2025-67280MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a...
CVE-2025-67279MEDIUM5.3An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi...
CVE-2025-67278MEDIUM6.5An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi...
CVE-2025-67133HIGH7.5An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component
CVE-2025-56225HIGH7.5fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be t...
CVE-2025-46676MEDIUM4.9Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-46644MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-46643MEDIUM4.4Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-15492HIGH8.8A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file s...
CVE-2025-14598CRITICAL9.8BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites....
CVE-2025-7072CRITICAL9.3The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route...
CVE-2025-66052HIGH7.2Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "...
CVE-2025-66051MEDIUM6.5Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated a...
CVE-2025-66050CRITICAL9.8Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as ...
CVE-2025-66049HIGH7.5Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera foo...
CVE-2025-14172MEDIUM6.5The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i...
CVE-2025-13967MEDIUM6.4The Woodpecker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_name' param...
CVE-2025-13908MEDIUM6.4The The Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'the_tooltip' shortco...
CVE-2025-13903MEDIUM6.4The PullQuote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pullquote' shortcode i...
CVE-2025-13897MEDIUM6.4The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial...
CVE-2025-13893MEDIUM6.1The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`...
CVE-2025-13892MEDIUM6.1The MG AdvancedOptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'...
CVE-2025-13862MEDIUM6.4The Menu Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `category` parameter in all vers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now