2025 CVE Vulnerabilities

45,259 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-53662MEDIUM6.5Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files ...
CVE-2025-53661MEDIUM4.3Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configurati...
CVE-2025-53660MEDIUM4.3Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job con...
CVE-2025-53659MEDIUM6.5Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml f...
CVE-2025-53658MEDIUM5.4Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a s...
CVE-2025-53657MEDIUM4.3Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and p...
CVE-2025-53656MEDIUM6.5Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and password...
CVE-2025-53655MEDIUM5.3Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, ...
CVE-2025-53654MEDIUM6.5Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration f...
CVE-2025-53653MEDIUM4.3Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml ...
CVE-2025-53652HIGH8.2Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to...
CVE-2025-53651MEDIUM6.3Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived du...
CVE-2025-53650HIGH7.3Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) ...
CVE-2025-49604MEDIUM5.4For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1...
CVE-2025-44526MEDIUM6.5Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields w...
CVE-2025-44177HIGH8.2A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically ...
CVE-2025-7204MEDIUM6.5In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sen...
CVE-2025-53546CRITICAL9.1Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-comm...
CVE-2025-52364HIGH7.5Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default a...
CVE-2025-2670MEDIUM4.3IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected securit...
CVE-2025-1112MEDIUM4.3IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only...
CVE-2025-6514CRITICAL9.6mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut...
CVE-2025-38264MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate ...
CVE-2025-38263MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: bcache: fix NULL pointer in cache_set_flush() 1. L...
CVE-2025-38262MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: tty: serial: uartlite: register uart driver in init...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now