5.4
CVE-2025-9865 -
Inappropriate implementation in Toolbar in Google Chrome on Android prior to 140.0.7339.80 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)
0.0
CVE-2025-9864 -
This CVE ID was assigned in error to a vulnerability that was both introduced and fixed before the code landed in the Stable channel of Chrome, and has been withdrawn.
5.1
CVE-2025-9920 - Campcodes Recruitment Management System index.php include file inclusion
A security flaw has been discovered in Campcodes Recruitment Management System 1.0. This impacts the function include of the file /admin/index.php. The manipulation of the argument page results in file inclusion. It is possible to launch the attack remotely. The exploit has been released to the pubโฆ
6.9
CVE-2025-9919 - 1000projects Beauty Parlour Management System bwdates-reports-details.php sql injection
A vulnerability was identified in 1000projects Beauty Parlour Management System 1.0. This affects an unknown function of the file /admin/bwdates-reports-details.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit โฆ
7.5
CVE-2025-0280 - HCL Compass is affected by a security vulnerability
A security vulnerability in HCL Compass can allow attacker to gain unauthorized database access.
4.2
CVE-2025-58460 -
A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
4.3
CVE-2025-58459 -
Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endpoints, allowing attackers with Overall/Read permission to enumerate graph IDs.
4.3
CVE-2025-58458 -
In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the specified file path exists on the controller when specifying `amazon-s3` protocol for use with JGit, allowing attackers with Overall/Read permission to check fโฆ
7.2
CVE-2025-58644 - WordPress LTL Freight Quotes - TQL Edition Plugin <= 1.2.6 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes - TQL Edition ltl-freight-quotes-tql-edition allows Object Injection.This issue affects LTL Freight Quotes - TQL Edition: from n/a through <= 1.2.6.
7.2
CVE-2025-58643 - WordPress LTL Freight Quotes โ Daylight Edition Plugin <= 2.2.7 - PHP Object Injection Vulnerability
Deserialization of Untrusted Data vulnerability in enituretechnology LTL Freight Quotes โ Daylight Edition ltl-freight-quotes-daylight-edition allows Object Injection.This issue affects LTL Freight Quotes โ Daylight Edition: from n/a through <= 2.2.7.