2025 CVE Vulnerabilities
45,347 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46406 | MEDIUM | 5.6 | 0.1% | Jul 10, 2025 | A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged Operator with high l... |
| CVE-2025-44003 | MEDIUM | 4.3 | 0.2% | Jul 10, 2025 | Missing Release of Resource after Effective Lifetime (CWE-772) in the Gallagher T-Series Reader allows an attacker with ... |
| CVE-2025-35983 | MEDIUM | 6.5 | 0.2% | Jul 10, 2025 | Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged atta... |
| CVE-2025-5807 | MEDIUM | 6.1 | 0.2% | Jul 10, 2025 | The Gwolle Guestbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gwolle_gb_content’ param... |
| CVE-2025-4406 | MEDIUM | 5.4 | 0.2% | Jul 10, 2025 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions ... |
| CVE-2025-6976 | MEDIUM | 5.4 | 0.2% | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-6975 | MEDIUM | 6.1 | 0.3% | Jul 9, 2025 | The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site S... |
| CVE-2025-0140 | MEDIUM | 6.8 | 0.1% | Jul 9, 2025 | An incorrect privilege assignment vulnerability in the Palo Alto Networks GlobalProtect™ App on macOS devices enables a ... |
| CVE-2025-0139 | MEDIUM | 6.3 | 0.1% | Jul 9, 2025 | An incorrect privilege assignment vulnerability in Palo Alto Networks Autonomous Digital Experience Manager allows a loc... |
| CVE-2025-52357 | MEDIUM | 4.1 | 0.3% | Jul 9, 2025 | Cross-Site Scripting (XSS) vulnerability exists in the ping diagnostic feature of FiberHome FD602GW-DX-R410 router (firm... |
| CVE-2025-36599 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulne... |
| CVE-2025-44525 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Texas Instruments CC2652RB LaunchPad SimpleLink CC13XX CC26XX SDK 7.41.00.17 was discovered to utilize insufficient perm... |
| CVE-2025-7381 | MEDIUM | 5.3 | 0.2% | Jul 9, 2025 | ImpactThis is an information disclosure vulnerability originating from PHP's base image. This vulnerability exposes the ... |
| CVE-2025-53743 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration f... |
| CVE-2025-53742 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the ... |
| CVE-2025-53678 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file... |
| CVE-2025-53677 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasi... |
| CVE-2025-53676 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on t... |
| CVE-2025-53675 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins con... |
| CVE-2025-53674 | MEDIUM | 5.3 | 0.3% | Jul 9, 2025 | Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global co... |
| CVE-2025-53673 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its glob... |
| CVE-2025-53672 | MEDIUM | 6.5 | 0.3% | Jul 9, 2025 | Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on ... |
| CVE-2025-53671 | MEDIUM | 6.5 | 0.2% | Jul 9, 2025 | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displ... |
| CVE-2025-53670 | MEDIUM | 6.5 | 0.1% | Jul 9, 2025 | Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted ... |
| CVE-2025-53669 | MEDIUM | 4.3 | 0.2% | Jul 9, 2025 | Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now