4.3

CVSS3.1

CVE-2025-64136 -

A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect to an attacker-specified HTTP server.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 4, 2025, 10:16 p.m.

5.9

CVSS3.1

CVE-2025-64135 -

Jenkins Eggplant Runner Plugin 0.0.1.301.v963cffe8ddb_8 and earlier sets the Java system property `jdk.http.auth.tunneling.disabledSchemes` to an empty value, disabling a protection mechanism of the Java runtime.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 3:23 p.m.

7.1

CVSS3.1

CVE-2025-64134 -

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Nov. 5, 2025, 5:35 p.m.

5.4

CVSS3.1

CVE-2025-64133 -

A cross-site request forgery (CSRF) vulnerability in Jenkins Extensible Choice Parameter Plugin 239.v5f5c278708cf and earlier allows attackers to execute sandboxed Groovy code.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 3:24 p.m.

5.4

CVSS3.1

CVE-2025-64132 -

Jenkins MCP Server Plugin 0.84.v50ca_24ef83f2 and earlier does not perform permission checks in multiple MCP tools, allowing attackers to trigger builds and obtain information about job and cloud configuration they should not be able to access.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 3:26 p.m.

7.5

CVSS3.1

CVE-2025-64131 -

Jenkins SAML Plugin 4.583.vc68232f7018a_ and earlier does not implement a replay cache, allowing attackers able to obtain information about the SAML authentication flow between a user's web browser and Jenkins to replay those requests, authenticating to Jenkins as that user.

๐Ÿ“… Published: Oct. 29, 2025, 1:29 p.m. ๐Ÿ”„ Last Modified: Dec. 22, 2025, 3:26 p.m.

4.3

CVSS3.1

CVE-2025-11587 - Call Now Button <= 1.5.3 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Settโ€ฆ

The Call Now Button โ€“ The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate function in all versions up to, and including, 1.5.3. This makes it possible for authenticated attackers, with Suโ€ฆ

๐Ÿ“… Published: Oct. 29, 2025, 12:31 p.m. ๐Ÿ”„ Last Modified: April 21, 2026, 6:45 p.m.

4.3

CVSS3.1

CVE-2025-11632 - Call Now Button <= 1.5.4 - Authenticated (Subscriber+) Missing Authorization to Multiple Functions

The Call Now Button โ€“ The #1 Click to Call Button for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with Subscriber-โ€ฆ

๐Ÿ“… Published: Oct. 29, 2025, 12:31 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 5 p.m.

6.9

CVSS4.0

CVE-2025-12142 - BSS(Block Started by Symbol) Memory Corruption Vulnerability

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33.

๐Ÿ“… Published: Oct. 29, 2025, noon ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-12461 - Unprotected access to parts of the application in Epsilon RH by Grupo Castilla

This vulnerability allows an attacker to access parts of the application that are not protected by any type of access control. The attacker could access this path โ€˜โ€ฆ/epsilonnet/License/About.aspxโ€™ and obtain information on both the licence and the configuration of the product by knowing which moduโ€ฆ

๐Ÿ“… Published: Oct. 29, 2025, 10:51 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 3227 of 34,919
ยซ previous page ยป next page
Filters