5.4

CVSS3.1

CVE-2025-64614 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

πŸ“… Published: Dec. 10, 2025, 6:22 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 5:39 p.m.

4.8

CVSS3.1

CVE-2025-64872 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they bro…

πŸ“… Published: Dec. 10, 2025, 6:22 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 5:32 p.m.

5.4

CVSS3.1

CVE-2025-64562 - Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)

Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute malicious scripts in the context of the victim's browser. Exploitation of this issue requires user interaction, s…

πŸ“… Published: Dec. 10, 2025, 6:22 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 7:55 p.m.

7.3

CVSS4.0

CVE-2025-65199 - Windscribe for Linux 'changeMTU' local privilege escalation

A command injection vulnerability exists in Windscribe for Linux Desktop App that allows a local user who is a member of the windscribe group to execute arbitrary commands as root via the 'adapterName' parameter of the 'changeMTU' function. Fixed in Windscribe v2.18.3-alpha and v2.18.8.

πŸ“… Published: Dec. 10, 2025, 6:04 p.m. πŸ”„ Last Modified: Dec. 23, 2025, 3:27 p.m.

1.9

CVSS4.0

CVE-2025-5467 - Ubuntu Apport Insecure File Permissions Vulnerability

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group ownership, possibly exposing crash information beyond expected or intended groups.

πŸ“… Published: Dec. 10, 2025, 6 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 5:12 p.m.

9.3

CVSS4.0

CVE-2025-13607 - D-Link CCTV camera model DCS-F5614-L1 Missing Authentication for Critical Function

A malicious actor can access camera configuration information, including account credentials, without authenticating when accessing a vulnerable URL.

πŸ“… Published: Dec. 10, 2025, 5:15 p.m. πŸ”„ Last Modified: Dec. 12, 2025, 3:18 p.m.

0.0

CVE-2025-14470 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

πŸ“… Published: Dec. 10, 2025, 5:03 p.m. πŸ”„ Last Modified: Jan. 12, 2026, 6:23 p.m.

4.3

CVSS3.1

CVE-2025-67643 -

Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and earlier does not correctly perform path validation of the workspace directory while uploading artifacts to Jira, allowing attackers with Item/Configure permission to retrieve files present on the Jenkins controller worksp…

πŸ“… Published: Dec. 10, 2025, 4:50 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 5:19 p.m.

4.3

CVSS3.1

CVE-2025-67642 -

Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing attackers with Item/Configure permission to access and potentially capture Vault credentials they are not entitled to.

πŸ“… Published: Dec. 10, 2025, 4:50 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 5:21 p.m.

8

CVSS3.1

CVE-2025-67641 -

Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through the UI, allowing attackers with Item/Configure permission to use a `javascript:` scheme URL as identif…

πŸ“… Published: Dec. 10, 2025, 4:50 p.m. πŸ”„ Last Modified: Dec. 17, 2025, 5:24 p.m.
Total resulsts: 342418
Page 2013 of 34,242
Β« previous page Β» next page
Filters