2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67280 | MEDIUM | 5.4 | 0.2% | Jan 9, 2026 | In TIM BPM Suite/ TIM FLOW through 9.1.2 multiple Hibernate Query Language injection vulnerabilities exist which allow a... |
| CVE-2025-67279 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi... |
| CVE-2025-67278 | MEDIUM | 6.5 | 0.3% | Jan 9, 2026 | An issue in TIM Solution GmbH TIM BPM Suite & TIM FLOW before v.9.1.2 allows a remote attacker to escalate privileges vi... |
| CVE-2025-46676 | MEDIUM | 4.9 | 0.3% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-46644 | MEDIUM | 6.7 | 0.5% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-46643 | MEDIUM | 4.4 | 0.1% | Jan 9, 2026 | Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4.... |
| CVE-2025-66051 | MEDIUM | 6.5 | 0.7% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a is vulnerable to path traversal. It is possible for an authenticated a... |
| CVE-2025-14172 | MEDIUM | 6.5 | 0.4% | Jan 9, 2026 | The WP Page Permalink Extension plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i... |
| CVE-2025-13967 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Woodpecker for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_name' param... |
| CVE-2025-13908 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The The Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'the_tooltip' shortco... |
| CVE-2025-13903 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The PullQuote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pullquote' shortcode i... |
| CVE-2025-13897 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Client Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'aft_testimonial... |
| CVE-2025-13893 | MEDIUM | 6.1 | 0.2% | Jan 9, 2026 | The Lesson Plan Book plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']`... |
| CVE-2025-13892 | MEDIUM | 6.1 | 0.3% | Jan 9, 2026 | The MG AdvancedOptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF'... |
| CVE-2025-13862 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Menu Card plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `category` parameter in all vers... |
| CVE-2025-13854 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Curved Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'radius' parameter of the arct... |
| CVE-2025-13852 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Debt.com Business in a Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'configuration'... |
| CVE-2025-13717 | MEDIUM | 5.3 | 0.3% | Jan 9, 2026 | The Contact Form vCard Generator plugin for WordPress is vulnerable to unauthorized access of data due to a missing capa... |
| CVE-2025-13704 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Autogen Headers Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'head_class' paramete... |
| CVE-2025-13701 | MEDIUM | 6.1 | 0.3% | Jan 9, 2026 | The Shabat Keeper plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] para... |
| CVE-2025-11453 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Header and Footer Scripts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the _inpost_head_scr... |
| CVE-2025-9222 | MEDIUM | 5.4 | 0.4% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and... |
| CVE-2025-13900 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The WP Popup Magic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the [wp... |
| CVE-2025-13895 | MEDIUM | 6.1 | 0.2% | Jan 9, 2026 | The Top Position Google Finance plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['... |
| CVE-2025-13853 | MEDIUM | 6.4 | 0.2% | Jan 9, 2026 | The Nearby Now Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_tech' parameter o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now