2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-67280MEDIUM5.4In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a...
CVE-2025-67279MEDIUM5.3An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi...
CVE-2025-67278MEDIUM6.5An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi...
CVE-2025-46676MEDIUM4.9Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-46644MEDIUM6.7Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-46643MEDIUM4.4Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-66051MEDIUM6.5Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated a...
CVE-2025-14172MEDIUM6.5The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i...
CVE-2025-13967MEDIUM6.4The Woodpecker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_name' param...
CVE-2025-13908MEDIUM6.4The The Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'the_tooltip' shortco...
CVE-2025-13903MEDIUM6.4The PullQuote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pullquote' shortcode i...
CVE-2025-13897MEDIUM6.4The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial...
CVE-2025-13893MEDIUM6.1The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`...
CVE-2025-13892MEDIUM6.1The MG AdvancedOptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'...
CVE-2025-13862MEDIUM6.4The Menu Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `category` parameter in all vers...
CVE-2025-13854MEDIUM6.4The Curved Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'radius' parameter of the arct...
CVE-2025-13852MEDIUM6.4The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration'...
CVE-2025-13717MEDIUM5.3The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa...
CVE-2025-13704MEDIUM6.4The Autogen Headers Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head_class' paramete...
CVE-2025-13701MEDIUM6.1The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] para...
CVE-2025-11453MEDIUM6.4The Header and Footer Scripts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _inpost_head_scr...
CVE-2025-9222MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and...
CVE-2025-13900MEDIUM6.4The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wp...
CVE-2025-13895MEDIUM6.1The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['...
CVE-2025-13853MEDIUM6.4The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter o...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now