Search

Found 20,975 results in 716ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-53742 unknown 11mo ago Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
CVE-2025-53678 unknown 11mo ago Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
CVE-2025-53676 unknown 11mo ago Jenkins Xooa Plugin vulnerability exposes unencrypted tokens to authenticated users
CVE-2025-53675 unknown 11mo ago Jenkins Warrior Framework Plugin vulnerability exposes unencrypted passwords to certain authenticated users
CVE-2025-53669 unknown 11mo ago Jenkins VAddy Plugin vulnerability exposes plaintext keys on its job configuration form
CVE-2025-53674 unknown 11mo ago Jenkins Sensedia API Platform Plugin vulnerability exposes unencrypted tokens
CVE-2025-53673 unknown 11mo ago Jenkins Sensedia API Platform Plugin vulnerability exposes unencrypted tokens in its global configuration file
CVE-2025-53672 unknown 11mo ago Jenkins Kryptowire Plugin vulnerability stores unencrypted Kryptowire API key
CVE-2025-53671 unknown 11mo ago Jenkins Nouvola DiveCloud Plugin vulnerability does not mask keys on its job configuration form
CVE-2025-53670 unknown 11mo ago Jenkins Nouvola DiveCloud Plugin vulnerability stores unencrypted credentials
CVE-2025-53668 unknown 11mo ago Jenkins VAddy Plugin vulnerability exposes unencrypted keys to certain authenticated users
CVE-2025-53667 unknown 11mo ago Jenkins Dead Man's Snitch Plugin vulnerability does not mask tokens
CVE-2025-53666 unknown 11mo ago Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text
CVE-2025-53665 unknown 11mo ago Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
CVE-2025-53664 unknown 11mo ago Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
CVE-2025-53663 unknown 11mo ago Jenkins IBM Cloud DevOps Plugin vulnerability exposes SonarQube authentication tokens
CVE-2025-53662 unknown 11mo ago Jenkins IFTTT Build Notifier Plugin vulnerability exposes IFTTT Maker Channel Keys
CVE-2025-53661 unknown 11mo ago Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
CVE-2025-53660 unknown 11mo ago Jenkins QMetry Test Management Plugin vulnerability exposes API keys
CVE-2025-53659 unknown 11mo ago Jenkins QMetry Test Management Plugin stores unencrypted API keys
CVE-2025-53658 unknown 11mo ago Jenkins Applitools Eyes Plugin vulnerable to XSS through its Build page
CVE-2025-53657 unknown 11mo ago Jenkins ReadyAPI Functional Testing Plugin vulnerability exposes secrets
CVE-2025-53656 unknown 11mo ago Jenkins ReadyAPI Functional Testing Plugin vulnerability stores unencrypted authentication credentials
CVE-2025-53655 unknown 11mo ago Jenkins Statistics Gatherer Plugin does not mask AWS Secret Key
CVE-2025-53654 unknown 11mo ago Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret Key
CVE-2025-53653 unknown 11mo ago Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens
CVE-2025-53652 unknown 11mo ago Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
CVE-2025-53651 unknown 11mo ago Jenkins HTML Publisher Plugin vulnerability displays controller file system information in its logs
CVE-2025-53650 unknown 11mo ago Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
CVE-2019-9621 unknown 2.5 KEVEXP 11mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.
CVE-2014-3931 unknown 1.5 KEV 11mo ago Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.
CVE-2025-53602 unknown 11mo ago Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
CVE-2025-6554 unknown 1.5 KEVFIX debian debian 11mo ago Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2025-53103 unknown FIX debian debian sles 11mo ago junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener
CVE-2025-48928 unknown 1.5 KEV 11mo ago TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equiv…
CVE-2025-48927 unknown 1.5 KEV 11mo ago TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump …
CVE-2025-53106 unknown 11mo ago Graylog vulnerable to privilege escalation through API tokens
CVE-2025-26074 unknown 11mo ago Conductor vulnerable to OS command injection through unrestricted access to Java classes
CVE-2025-53003 unknown 11mo ago Janssen Config API returns results without scope verification
CVE-2025-6543 unknown 1.5 KEV 11mo ago Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Pro…
CVE-2025-53393 unknown 11mo ago akka-cluster-metrics uses Java serialization for cluster metrics
CVE-2025-32897 unknown 11mo ago Apache Seata Vulnerable to Deserialization of Untrusted Data
CVE-2025-5731 unknown 1y ago Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2025-52890 unknown FIX debian debian 1y ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security optio…
CVE-2025-52889 unknown FIX debian debian 1y ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) th…
CVE-2025-52888 unknown 1y ago Allure Report allows Improper XXE Restriction via DocumentBuilderFactory
CVE-2024-54085 unknown 1.5 KEV 1y ago AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integ…
CVE-2024-0769 unknown 1.5 KEV 1y ago D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdoc…
CVE-2019-6693 unknown 1.5 KEV 1y ago Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
CVE-2025-49574 unknown 1y ago Quarkus potentially leaks data when duplicating a duplicated context
CVE-2025-6384 unknown 1y ago Crafter Studio Groovy Sandbox Bypass
CVE-2025-48059 unknown 1y ago PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion
CVE-2025-48058 unknown 1y ago PowSyBl Core contains Polynomial REDoS’es
CVE-2025-47771 unknown 1y ago PowSyBl Core allows deserialization of untrusted SparseMatrix data
CVE-2025-47293 unknown 1y ago PowSyBl Core XML Reader allows XXE and SSRF
CVE-2025-32896 unknown 1y ago Apache SeaTunnel: Unauthenticated insecure access
CVE-2022-49957 unknown FIX slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initial…
CVE-2025-3248 unknown 2.5 KEVEXP 1y ago Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
CVE-2025-49124 unknown FIX slesdebian debian 1y ago Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects A…
CVE-2025-3594 unknown 1y ago Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
CVE-2025-3526 unknown 1y ago Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
CVE-2025-3602 unknown 1y ago Liferay Portal does not limit the depth of a GraphQL queries
CVE-2025-43200 unknown 1.5 KEV 1y ago Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
CVE-2023-33538 unknown 1.5 KEV 1y ago TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) an…
CVE-2025-49585 unknown 1y ago XWiki does not require right warnings for XClass definitions
CVE-2025-49586 unknown 1y ago XWiki allows remote code execution through preview of XClass changes in AWM editor
CVE-2025-49587 unknown 1y ago XWiki does not require right warnings for notification displayer objects
CVE-2025-49584 unknown 1y ago XWiki makes title of inaccessible pages available through the class property values REST API
CVE-2025-49583 unknown 1y ago XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
CVE-2025-49581 unknown 1y ago XWiki allows remote code execution through default value of wiki macro wiki-type parameters
CVE-2025-49582 unknown 1y ago XWiki's required right warnings for macros are incomplete
CVE-2025-49580 unknown 1y ago XWiki allows privilege escalation through link refactoring
CVE-2025-46096 unknown 1y ago Solon Vulnerable to Directory Traversal
CVE-2025-41234 unknown FIX debian debian 1y ago Spring Framework vulnerable to a reflected file download (RFD)
CVE-2024-56158 unknown 1y ago XWiki allows SQL injection in query endpoint of REST API with Oracle
CVE-2025-49146 unknown FIX debian debian sles 1y ago pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
CVE-2025-30220 unknown 1y ago [XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
CVE-2025-30145 unknown 1y ago GeoServer Infinite Loop Vulnerability in Jiffle process
CVE-2025-27505 unknown 1y ago GeoServer Missing Authorization on REST API Index
CVE-2024-40625 unknown 1y ago Coverage REST API Server Side Request Forgery
CVE-2024-38524 unknown 1y ago GWC Home Page communicate version and revision information
CVE-2024-34711 unknown 1y ago GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
CVE-2024-29198 unknown 1y ago GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
CVE-2025-27819 unknown 1y ago Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27818 unknown 1y ago Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27817 unknown 1y ago Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
CVE-2025-33053 unknown 2.5 KEVEXP 1y ago Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribut…
CVE-2025-32433 unknown 2.5 KEVEXPFIX debian debian sles 1y ago Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially l…
CVE-2024-42009 unknown 1.5 KEVFIX debian debian 1y ago RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desan…
CVE-2025-49128 unknown FIX debian debian 1y ago Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
CVE-2025-49009 unknown 1y ago Para Inserts Sensitive Information into Log File for Facebook authentication
CVE-2025-5806 unknown 1y ago Jenkins Gatling Plugin Vulnerable to Cross-Site Scripting (XSS)
CVE-2025-27531 unknown 1y ago Apache InLong Deserialization of Untrusted Data Vulnerability
CVE-2025-5419 unknown 1.5 KEVFIX debian debian 1y ago Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-35036 unknown debian debian 1y ago Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
CVE-2025-46548 unknown 1y ago Pekko Management may not properly apply authenticator when Basic Authentication is enabled
CVE-2025-45855 unknown 1y ago Erupt Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2025-27038 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVE-2025-21480 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing spe…
CVE-2025-21479 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing spe…