Latest CVE Feed
-
7.3
HIGHCVE-2025-53650
Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build log.... Read more
Affected Products : credentials_binding- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-44526
Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows attackers to cause a Denial of Service (DoS) via a crafted LL_Length_R... Read more
- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Denial of Service
-
4.3
MEDIUMCVE-2025-53653
Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controll... Read more
Affected Products : aqua_security_scanner- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-53654
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.... Read more
Affected Products : statistics_gatherer- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Misconfiguration
-
5.3
MEDIUMCVE-2025-53655
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.... Read more
Affected Products : statistics_gatherer- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-53660
Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : qmetry_test_management- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-53659
Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controlle... Read more
Affected Products : qmetry_test_management- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
5.4
MEDIUMCVE-2025-53658
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.... Read more
Affected Products : applitools_eyes- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2025-53657
Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : readyapi_functional_testing- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-53656
Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission o... Read more
Affected Products : readyapi_functional_testing- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2025-53661
Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : testsigma_test_plan_run- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-53662
Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller fil... Read more
Affected Products : ifttt_build_notifier- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-53663
Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controll... Read more
Affected Products : ibm_cloud_devops- Published: Jul. 09, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-51630
TOTOLINK N350RT V9.3.5u.6139_B20201216 was discovered to contain a buffer overflow via the ePort parameter in the function setIpPortFilterRules.... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-20674
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Pat... Read more
Affected Products : openwrt mt7915_firmware mt7916_firmware mt7981_firmware mt7986_firmware mt6890 mt6990 mt7915 mt7916 mt7986 +8 more products- Published: Jun. 02, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Authentication
-
9.5
CRITICALCVE-2025-4318
The AWS Amplify Studio UI component property expressions in the aws-amplify/amplify-codegen-ui package lack input validation. This could potentially allow an authenticated user who has access to create or modify components to run arbitrary JavaScript code... Read more
Affected Products :- Published: May. 05, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Cross-Site Scripting
-
9.0
HIGHCVE-2025-7747
A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. This affects the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. The manipulation of the argument PPW leads to buffer overflow.... Read more
- Published: Jul. 17, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-7749
A vulnerability, which was classified as critical, has been found in code-projects Online Appointment Booking System 1.0. This issue affects some unknown processing of the file /admin/getmanagerregion.php. The manipulation of the argument city leads to sq... Read more
Affected Products : online_appointment_booking_system- Published: Jul. 17, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Injection
-
6.3
MEDIUMCVE-2025-7095
A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulation leads to improper certificate validation. It is possible to initiate the ... Read more
Affected Products : internet_security- Published: Jul. 06, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Misconfiguration
-
8.4
HIGHCVE-2025-53367
DjVuLibre is a GPL implementation of DjVu, a web-centric format for distributing documents and images. Prior to version 3.5.29, the MMRDecoder::scanruns method is affected by an OOB-write vulnerability, because it does not check that the xr pointer stays ... Read more
Affected Products : djvulibre- Published: Jul. 03, 2025
- Modified: Jul. 18, 2025
- Vuln Type: Memory Corruption