7.1

CVSS4.0

CVE-2025-6376 - Arena® Simulation Out-Of-Bounds Write Remote Code Execution Vulnerability

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat…

📅 Published: July 9, 2025, 8:13 p.m. 🔄 Last Modified: July 11, 2025, 6:35 p.m.

7.1

CVSS4.0

CVE-2025-6377 - Arena® Simulation Out-Of-Bounds Write Remote Code Execution Vulnerability

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat…

📅 Published: July 9, 2025, 8:12 p.m. 🔄 Last Modified: July 11, 2025, 6:34 p.m.

9.2

CVSS4.0

CVE-2025-53620 - Crashing any Qwik Server

@builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit. This vulnerability is fixed in 1.13.…

📅 Published: July 9, 2025, 6:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2025-36599 -

Dell PowerFlex Manager VM, versions prior to 4.6.2.1, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be abl…

📅 Published: July 9, 2025, 6:30 p.m. 🔄 Last Modified: Jan. 16, 2026, 3 p.m.

7.5

CVSS3.1

CVE-2025-53548 - @clerk/backend Performs Insufficient Verification of Data Authenticity

Clerk helps developers build user management. Applications that use the verifyWebhook() helper to verify incoming Clerk webhooks are susceptible to accepting improperly signed webhook events. The issue was resolved in @clerk/backend 2.4.0.

📅 Published: July 9, 2025, 5:12 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2025-53743 -

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

📅 Published: July 9, 2025, 3:39 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53742 -

Jenkins Applitools Eyes Plugin 1.16.5 and earlier stores Applitools API keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

📅 Published: July 9, 2025, 3:39 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53678 -

Jenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.

📅 Published: July 9, 2025, 3:39 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

5.3

CVSS3.1

CVE-2025-53677 -

Jenkins Xooa Plugin 0.0.7 and earlier does not mask the Xooa Deployment Token on the global configuration form, increasing the potential for attackers to observe and capture it.

📅 Published: July 9, 2025, 3:39 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

6.5

CVSS3.1

CVE-2025-53676 -

Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.

📅 Published: July 9, 2025, 3:39 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.
Total resulsts: 349182
Page 4702 of 34,919
« previous page » next page
Filters