2025 CVE Vulnerabilities
45,259 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53662 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files ... |
| CVE-2025-53661 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configurati... |
| CVE-2025-53660 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job con... |
| CVE-2025-53659 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml f... |
| CVE-2025-53658 | MEDIUM | 5.4 | 0.2% | Jul 9, 2025 | Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a s... |
| CVE-2025-53657 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and p... |
| CVE-2025-53656 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and password... |
| CVE-2025-53655 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, ... |
| CVE-2025-53654 | MEDIUM | 6.5 | 0.4% | Jul 9, 2025 | Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration f... |
| CVE-2025-53653 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml ... |
| CVE-2025-53652 | HIGH | 8.2 | 0.6% | Jul 9, 2025 | Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to... |
| CVE-2025-53651 | MEDIUM | 6.3 | 0.4% | Jul 9, 2025 | Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived du... |
| CVE-2025-53650 | HIGH | 7.3 | 0.3% | Jul 9, 2025 | Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) ... |
| CVE-2025-49604 | MEDIUM | 5.4 | 0.3% | Jul 9, 2025 | For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1... |
| CVE-2025-44526 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields w... |
| CVE-2025-44177 | HIGH | 8.2 | 4.2% | Jul 9, 2025 | A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically ... |
| CVE-2025-7204 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sen... |
| CVE-2025-53546 | CRITICAL | 9.1 | 0.3% | Jul 9, 2025 | Folo organizes feeds content into one timeline. Using pull_request_target on .github/workflows/auto-fix-lint-format-comm... |
| CVE-2025-52364 | HIGH | 7.5 | 0.5% | Jul 9, 2025 | Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service (telnetd) by default a... |
| CVE-2025-2670 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected securit... |
| CVE-2025-1112 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only... |
| CVE-2025-6514 | CRITICAL | 9.6 | 76.6% | Jul 9, 2025 | mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut... |
| CVE-2025-38264 | MEDIUM | 5.5 | 0.1% | Jul 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate ... |
| CVE-2025-38263 | MEDIUM | 5.5 | 0.1% | Jul 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: bcache: fix NULL pointer in cache_set_flush() 1. L... |
| CVE-2025-38262 | MEDIUM | 5.5 | 0.1% | Jul 9, 2025 | In the Linux kernel, the following vulnerability has been resolved: tty: serial: uartlite: register uart driver in init... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now