2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64148 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read per... |
| CVE-2025-64147 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the p... |
| CVE-2025-64146 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller wh... |
| CVE-2025-64145 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing ... |
| CVE-2025-64144 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controll... |
| CVE-2025-64143 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on ... |
| CVE-2025-64142 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read perm... |
| CVE-2025-64141 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers... |
| CVE-2025-64139 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Rea... |
| CVE-2025-64138 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows att... |
| CVE-2025-64137 | MEDIUM | 4.3 | 0.3% | Oct 29, 2025 | A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to c... |
| CVE-2025-64136 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect... |
| CVE-2025-64135 | MEDIUM | 5.9 | 0.3% | Oct 29, 2025 | Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneli... |
| CVE-2025-64133 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and ea... |
| CVE-2025-64132 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allo... |
| CVE-2025-11632 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized acces... |
| CVE-2025-11587 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2025-12142 | MEDIUM | 6.9 | 0.2% | Oct 29, 2025 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This issue ... |
| CVE-2025-12461 | MEDIUM | 6.9 | 0.3% | Oct 29, 2025 | This vulnerability allows an attacker to access parts of the application that are not protected by any type of access co... |
| CVE-2025-12450 | MEDIUM | 6.1 | 0.4% | Oct 29, 2025 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to,... |
| CVE-2025-64291 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerc... |
| CVE-2025-64290 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search a... |
| CVE-2025-64289 | MEDIUM | 5.9 | 0.2% | Oct 29, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerc... |
| CVE-2025-64288 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Premmerce Premmerce premmerce allows Cross Site Request Forgery.This ... |
| CVE-2025-64286 | MEDIUM | 4.3 | 0.1% | Oct 29, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WpEstate WP Rentals wprentals allows Cross Site Request Forgery.This ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now