7.6

CVSS4.0

CVE-2025-47783 - label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.

Label Studio is a multi-type data labeling and annotation tool. A vulnerability in versions prior to 1.18.0 allows an attacker to inject a malicious script into the context of a web page, which can lead to data theft, session hijacking, unauthorized actions on behalf of the user, and other attacks.…

πŸ“… Published: May 14, 2025, 11:01 p.m. πŸ”„ Last Modified: Aug. 22, 2025, 8:24 p.m.

6.6

CVSS3.1

CVE-2025-46836 - net-tools Stack-based Buffer Overflow vulnerability

net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (like ifconfig) from the net-tools package do not properly validate the structure of /proc files when …

πŸ“… Published: May 14, 2025, 10:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2025-32421 - Next.js Race Condition to Cache Poisoning

Next.js is a React framework for building full-stack web applications. Versions prior to 14.2.24 and 15.1.6 have a race-condition vulnerability. This issue only affects the Pages Router under certain misconfigurations, causing normal endpoints to serve `pageProps` data instead of standard HTML. Thi…

πŸ“… Published: May 14, 2025, 10:56 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 3:16 p.m.

5.4

CVSS4.0

CVE-2024-45067 -

Incorrect default permissions in some Intel(R) Gaudi(R) software installers before version 1.18 may allow an authenticated user to potentially enable escalation of privilege via local access.

πŸ“… Published: May 14, 2025, 10:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2025-47889 -

In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" security realm, allowing unauthenticated attackers to log in to controllers using this security realm using any username and any password, including usernames that do not exist.

πŸ“… Published: May 14, 2025, 8:35 p.m. πŸ”„ Last Modified: June 12, 2025, 1:23 p.m.

5.9

CVSS3.1

CVE-2025-47888 -

Jenkins DingTalk Plugin 2.7.3 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections to the configured DingTalk webhooks.

πŸ“… Published: May 14, 2025, 8:35 p.m. πŸ”„ Last Modified: June 12, 2025, 1:26 p.m.

4.3

CVSS3.1

CVE-2025-47887 -

Missing permission checks in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified username and password.

πŸ“… Published: May 14, 2025, 8:35 p.m. πŸ”„ Last Modified: June 12, 2025, 1:33 p.m.

4.3

CVSS3.1

CVE-2025-47886 -

A cross-site request forgery (CSRF) vulnerability in Jenkins Cadence vManager Plugin 4.0.1-286.v9e25a_740b_a_48 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified username and password.

πŸ“… Published: May 14, 2025, 8:35 p.m. πŸ”„ Last Modified: June 12, 2025, 1:36 p.m.

8.8

CVSS3.1

CVE-2025-47885 -

Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses.

πŸ“… Published: May 14, 2025, 8:35 p.m. πŸ”„ Last Modified: June 12, 2025, 1:47 p.m.

9.1

CVSS3.1

CVE-2025-47884 -

In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentially overridden values of environment variables, in conjunction with certain other plugins allowing attackers able to configure jobs to craft a build ID Token that impersonates a tru…

πŸ“… Published: May 14, 2025, 8:35 p.m. πŸ”„ Last Modified: June 12, 2025, 1:48 p.m.
Total resulsts: 346087
Page 5099 of 34,609
Β« previous page Β» next page
Filters