2025 CVE Vulnerabilities

45,347 CVEs published in 2025.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2025-46406MEDIUM5.6A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l...
CVE-2025-44003MEDIUM4.3Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with ...
CVE-2025-35983MEDIUM6.5Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged atta...
CVE-2025-5807MEDIUM6.1The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ param...
CVE-2025-4406MEDIUM5.4The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ...
CVE-2025-6976MEDIUM5.4The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri...
CVE-2025-6975MEDIUM6.1The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S...
CVE-2025-0140MEDIUM6.8An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ...
CVE-2025-0139MEDIUM6.3An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a loc...
CVE-2025-52357MEDIUM4.1Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firm...
CVE-2025-36599MEDIUM6.5Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulne...
CVE-2025-44525MEDIUM6.5Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient perm...
CVE-2025-7381MEDIUM5.3ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the ...
CVE-2025-53743MEDIUM5.3Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration f...
CVE-2025-53742MEDIUM6.5Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the ...
CVE-2025-53678MEDIUM6.5Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file...
CVE-2025-53677MEDIUM5.3Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasi...
CVE-2025-53676MEDIUM6.5Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on t...
CVE-2025-53675MEDIUM6.5Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins con...
CVE-2025-53674MEDIUM5.3Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global co...
CVE-2025-53673MEDIUM6.5Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its glob...
CVE-2025-53672MEDIUM6.5Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on ...
CVE-2025-53671MEDIUM6.5Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displ...
CVE-2025-53670MEDIUM6.5Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted ...
CVE-2025-53669MEDIUM4.3Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now