2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-64146MEDIUM4.3Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller wh...
CVE-2025-64145MEDIUM4.3Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing ...
CVE-2025-64144MEDIUM4.3Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controll...
CVE-2025-64143MEDIUM4.3Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on ...
CVE-2025-64142MEDIUM4.3A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read perm...
CVE-2025-64141MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers...
CVE-2025-64140HIGH8.8Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowin...
CVE-2025-64139MEDIUM4.3A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Rea...
CVE-2025-64138MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows att...
CVE-2025-64137MEDIUM4.3A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to c...
CVE-2025-64136MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect...
CVE-2025-64135MEDIUM5.9Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneli...
CVE-2025-64134HIGH7.1Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure it...
CVE-2025-64133MEDIUM5.4A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and ea...
CVE-2025-64132MEDIUM5.4Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allo...
CVE-2025-64131HIGH7.5Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtai...
CVE-2025-61161HIGH8.4DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an un...
CVE-2025-40085In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_...
CVE-2025-40084HIGH7.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before ...
CVE-2025-40083In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix null-deref in agg_dequeue ...
CVE-2025-11632MEDIUM4.3The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized acces...
CVE-2025-11587MEDIUM4.3The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modif...
CVE-2025-12142MEDIUM6.9Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This issue ...
CVE-2025-12461MEDIUM6.9This vulnerability allows an attacker to access parts of the application that are not protected by any type of access co...
CVE-2025-12450MEDIUM6.1The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now