2025 CVE Vulnerabilities

45,259 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52357MEDIUM4.1Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firm...
CVE-2025-53620CRITICAL9.2@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the ...
CVE-2025-36599MEDIUM6.5Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulne...
CVE-2025-53548HIGH7.5Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk ...
CVE-2025-53645HIGH7.5Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a den...
CVE-2025-44525MEDIUM6.5Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient perm...
CVE-2025-7381MEDIUM5.3ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the ...
CVE-2025-53743MEDIUM5.3Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration f...
CVE-2025-53742MEDIUM6.5Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the ...
CVE-2025-53678MEDIUM6.5Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file...
CVE-2025-53677MEDIUM5.3Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasi...
CVE-2025-53676MEDIUM6.5Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on t...
CVE-2025-53675MEDIUM6.5Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins con...
CVE-2025-53674MEDIUM5.3Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global co...
CVE-2025-53673MEDIUM6.5Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its glob...
CVE-2025-53672MEDIUM6.5Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on ...
CVE-2025-53671MEDIUM6.5Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displ...
CVE-2025-53670MEDIUM6.5Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted ...
CVE-2025-53669MEDIUM4.3Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increa...
CVE-2025-53668MEDIUM6.5Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins con...
CVE-2025-53667MEDIUM5.3Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, inc...
CVE-2025-53666MEDIUM6.5Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins ...
CVE-2025-53665MEDIUM4.3Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the j...
CVE-2025-53664MEDIUM6.5Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config...
CVE-2025-53663MEDIUM6.5Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now