4.3

CVSS3.1

CVE-2025-24400 -

Jenkins Eiffel Broadcaster Plugin 2.8.0 through 2.10.2 (both inclusive) uses the credential ID as the cache key during signing operations, allowing attackers able to create a credential with the same ID as a legitimate one in a different credentials store to sign an event published to RabbitMQ with…

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:16 a.m.

8.8

CVSS3.1

CVE-2025-24399 -

Jenkins OpenId Connect Authentication Plugin 4.452.v2849b_d3945fa_ and earlier, except 4.438.440.v3f5f201de5dc, treats usernames as case-insensitive, allowing attackers on Jenkins instances configured with a case-sensitive OpenID Connect provider to log in as any user by providing a username that d…

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: May 7, 2025, 8:03 p.m.

8.8

CVSS3.1

CVE-2025-24398 -

Jenkins Bitbucket Server Integration Plugin 2.1.0 through 4.1.3 (both inclusive) allows attackers to craft URLs that would bypass the CSRF protection of any target URL in Jenkins.

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: June 6, 2025, 3:23 p.m.

4.3

CVSS3.1

CVE-2025-24397 -

An incorrect permission check in Jenkins GitLab Plugin 1.9.6 and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credential IDs of GitLab API token and Secret text credentials stored in Jenkins.

πŸ“… Published: Jan. 22, 2025, 5:02 p.m. πŸ”„ Last Modified: Oct. 3, 2025, 12:19 a.m.

5.3

CVSS3.1

CVE-2025-23028 - DoS in Cilium agent DNS proxy from crafted DNS responses

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. A denial of service vulnerability affects versions 1.14.0 through 1.14.7, 1.15.0 through 1.15.11, and 1.16.0 through 1.16.4. In a Kubernetes cluster where Cilium is configured to proxy DNS traffic, an attacke…

πŸ“… Published: Jan. 22, 2025, 4:48 p.m. πŸ”„ Last Modified: Sept. 3, 2025, 5:17 p.m.

4.4

CVSS3.1

CVE-2024-51457 - IBM Robotic Process Automation for Cloud Pak cross-site scripting

IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr…

πŸ“… Published: Jan. 22, 2025, 4:36 p.m. πŸ”„ Last Modified: Aug. 18, 2025, 5:57 p.m.

7.5

CVSS3.1

CVE-2025-20165 - Cisco BroadWorks SIP Denial of Service Vulnerability

A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition. This vulnerability is due to improper memory handling for certain SIP requests. A…

πŸ“… Published: Jan. 22, 2025, 4:21 p.m. πŸ”„ Last Modified: Aug. 6, 2025, 8:02 p.m.

9.9

CVSS3.1

CVE-2025-20156 - Cisco Meeting Management Client-Server Privilege Escalation Vulnerability

A vulnerability in the REST API of Cisco Meeting Management could allow a remote, authenticated attacker with low privileges to elevate privileges to administrator on an affected device. This vulnerability exists because proper authorization is not enforced upon REST API users. An attacker …

πŸ“… Published: Jan. 22, 2025, 4:21 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:08 p.m.

5.3

CVSS3.1

CVE-2025-20128 - ClamAV OLE2 File Format Decryption Denial of Service Vulnerability

A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap…

πŸ“… Published: Jan. 22, 2025, 4:21 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 7:15 p.m.

8.8

CVSS3.1

CVE-2024-31903 - IBM Sterling B2B Integrator Standard Edition code execution

IBM Sterling B2B Integrator Standard EditionΒ 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.2 allow an attacker on the local network to execute arbitrary code on the system, caused by the deserialization of untrusted data.

πŸ“… Published: Jan. 22, 2025, 4:08 p.m. πŸ”„ Last Modified: March 5, 2025, 4:02 p.m.
Total resulsts: 349182
Page 6996 of 34,919
Β« previous page Β» next page
Filters