2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67282 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Authorization Bypass vulnerabilities exists which allow a low privileg... |
| CVE-2025-67281 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple SQL injection vulnerabilities exists which allow a low privileged and ... |
| CVE-2025-67280 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a... |
| CVE-2025-67279 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi... |
| CVE-2025-67278 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi... |
| CVE-2025-67133 | HIGH | 7.5 | 0.5% | Jan 9, 2026 | An issue in Hero Motocorp Vida V1 Pro 2.0.7 allows a local attacker to cause a denial of service via the BLE component |
| CVE-2025-56225 | HIGH | 7.5 | 0.4% | Jan 9, 2026 | fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be t... |
| CVE-2025-46676 | MEDIUM | 4.9 | 0.3% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-46644 | MEDIUM | 6.7 | 0.5% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-46643 | MEDIUM | 4.4 | 0.1% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-15492 | HIGH | 8.8 | 0.4% | Jan 9, 2026 | A vulnerability was detected in RainyGao DocSys up to 2.02.36. The affected element is an unknown function of the file s... |
| CVE-2025-14598 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites.... |
| CVE-2025-7072 | CRITICAL | 9.3 | 0.5% | Jan 9, 2026 | The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route... |
| CVE-2025-66052 | HIGH | 7.2 | 1.3% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to command injection. Parameter "system_ntpIt" used by "... |
| CVE-2025-66051 | MEDIUM | 6.5 | 0.7% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated a... |
| CVE-2025-66050 | CRITICAL | 9.8 | 0.3% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as ... |
| CVE-2025-66049 | HIGH | 7.5 | 0.4% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to an information disclosure issue where live camera foo... |
| CVE-2025-14172 | MEDIUM | 6.5 | 0.4% | Jan 9, 2026 | The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i... |
| CVE-2025-13967 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Woodpecker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_name' param... |
| CVE-2025-13908 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The The Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'the_tooltip' shortco... |
| CVE-2025-13903 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The PullQuote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pullquote' shortcode i... |
| CVE-2025-13897 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial... |
| CVE-2025-13893 | MEDIUM | 6.1 | 0.2% | Jan 9, 2026 | The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`... |
| CVE-2025-13892 | MEDIUM | 6.1 | 0.3% | Jan 9, 2026 | The MG AdvancedOptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'... |
| CVE-2025-13862 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Menu Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `category` parameter in all vers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now