2025 CVE Vulnerabilities
45,259 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52357 | MEDIUM | 4.1 | 0.3% | Jul 9, 2025 | Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firm... |
| CVE-2025-53620 | CRITICAL | 9.2 | 0.3% | Jul 9, 2025 | @builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the ... |
| CVE-2025-36599 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulne... |
| CVE-2025-53548 | HIGH | 7.5 | 0.2% | Jul 9, 2025 | Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk ... |
| CVE-2025-53645 | HIGH | 7.5 | 1.3% | Jul 9, 2025 | Zimbra Collaboration (ZCS) before 9.0.0 Patch 46, 10.0.x before 10.0.15, and 10.1.x before 10.1.9 is vulnerable to a den... |
| CVE-2025-44525 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient perm... |
| CVE-2025-7381 | MEDIUM | 5.3 | 0.2% | Jul 9, 2025 | ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the ... |
| CVE-2025-53743 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration f... |
| CVE-2025-53742 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the ... |
| CVE-2025-53678 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file... |
| CVE-2025-53677 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasi... |
| CVE-2025-53676 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on t... |
| CVE-2025-53675 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins con... |
| CVE-2025-53674 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global co... |
| CVE-2025-53673 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its glob... |
| CVE-2025-53672 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on ... |
| CVE-2025-53671 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displ... |
| CVE-2025-53670 | MEDIUM | 6.5 | 0.1% | Jul 9, 2025 | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted ... |
| CVE-2025-53669 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increa... |
| CVE-2025-53668 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins con... |
| CVE-2025-53667 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, inc... |
| CVE-2025-53666 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins ... |
| CVE-2025-53665 | MEDIUM | 4.3 | 0.3% | Jul 9, 2025 | Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the j... |
| CVE-2025-53664 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config... |
| CVE-2025-53663 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now