4.3

CVSS3.1

CVE-2025-24402 -

A cross-site request forgery (CSRF) vulnerability in Jenkins Azure Service Fabric Plugin 1.6 and earlier allows attackers to connect to a Service Fabric URL using attacker-specified credentials IDs obtained through another method.

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:13 a.m.

6.8

CVSS3.1

CVE-2025-24401 -

Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitl…

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:15 a.m.

4.3

CVSS3.1

CVE-2025-24400 -

Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with…

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:16 a.m.

8.8

CVSS3.1

CVE-2025-24399 -

Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that d…

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: May 7, 2025, 8:03 p.m.

8.8

CVSS3.1

CVE-2025-24398 -

Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: June 6, 2025, 3:23 p.m.

4.3

CVSS3.1

CVE-2025-24397 -

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:19 a.m.

5.3

CVSS3.1

CVE-2025-23028 - DoS in Cilium agent DNS proxy from crafted DNS responses

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. In a Kubernetes cluster where Cilium is configured to proxy DNS traffic, an attacke…

πŸ“… Published: Jan. 22, 2025, 4:48 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 5:17 p.m.

4.4

CVSS3.1

CVE-2024-51457 - IBM Robotic Process Automation for Cloud Pak cross-site scripting

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr…

πŸ“… Published: Jan. 22, 2025, 4:36 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 5:57 p.m.

7.5

CVSS3.1

CVE-2025-20165 - Cisco BroadWorks SIP Denial of Service Vulnerability

A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition. This vulnerability is due to improper memory handling for certain SIP requests. A…

πŸ“… Published: Jan. 22, 2025, 4:21 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:02 p.m.

9.9

CVSS3.1

CVE-2025-20156 - Cisco Meeting Management Client-Server Privilege Escalation Vulnerability

A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker …

πŸ“… Published: Jan. 22, 2025, 4:21 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.
Total resulsts: 346624
Page 6740 of 34,663
Β« previous page Β» next page
Filters