2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64146 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller wh... |
| CVE-2025-64145 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing ... |
| CVE-2025-64144 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controll... |
| CVE-2025-64143 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on ... |
| CVE-2025-64142 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read perm... |
| CVE-2025-64141 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers... |
| CVE-2025-64140 | HIGH | 8.8 | 0.6% | Oct 29, 2025 | Jenkins Azure CLI Plugin 0.9 and earlier does not restrict which commands it executes on the Jenkins controller, allowin... |
| CVE-2025-64139 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Rea... |
| CVE-2025-64138 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows att... |
| CVE-2025-64137 | MEDIUM | 4.3 | 0.3% | Oct 29, 2025 | A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to c... |
| CVE-2025-64136 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect... |
| CVE-2025-64135 | MEDIUM | 5.9 | 0.3% | Oct 29, 2025 | Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneli... |
| CVE-2025-64134 | HIGH | 7.1 | 0.3% | Oct 29, 2025 | Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure it... |
| CVE-2025-64133 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and ea... |
| CVE-2025-64132 | MEDIUM | 5.4 | 0.2% | Oct 29, 2025 | Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allo... |
| CVE-2025-64131 | HIGH | 7.5 | 0.4% | Oct 29, 2025 | Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtai... |
| CVE-2025-61161 | HIGH | 8.4 | 0.2% | Oct 29, 2025 | DLL hijacking vulnerability in Evope Collector 1.1.6.9.0 and related components load the wtsapi32.dll library from an un... |
| CVE-2025-40085 | — | — | 0.2% | Oct 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Fix NULL pointer deference in try_... |
| CVE-2025-40084 | HIGH | 7.1 | 0.2% | Oct 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: transport_ipc: validate payload size before ... |
| CVE-2025-40083 | — | — | 0.2% | Oct 29, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix null-deref in agg_dequeue ... |
| CVE-2025-11632 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized acces... |
| CVE-2025-11587 | MEDIUM | 4.3 | 0.2% | Oct 29, 2025 | The Call Now Button – The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2025-12142 | MEDIUM | 6.9 | 0.2% | Oct 29, 2025 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This issue ... |
| CVE-2025-12461 | MEDIUM | 6.9 | 0.3% | Oct 29, 2025 | This vulnerability allows an attacker to access parts of the application that are not protected by any type of access co... |
| CVE-2025-12450 | MEDIUM | 6.1 | 0.4% | Oct 29, 2025 | The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URLs in all versions up to,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now