Latest CVE Feed
- 
                                
                                
9.8
CRITICALCVE-2025-10561
The device is running an outdated operating system, which may be susceptible to known vulnerabilities.... Read more
- Published: Oct. 27, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
7.5
HIGHCVE-2025-12326
A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This vulnerability affects unknown code of the file /process.php of the component POST Request Handler. The manipulation of the argument un results in sql injec... Read more
Affected Products : ruet_oj- Published: Oct. 27, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
6.5
MEDIUMCVE-2025-12327
A vulnerability was determined in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. This issue affects some unknown processing of the file /description.php. This manipulation of the argument ID causes sql injection. The attack may be initi... Read more
Affected Products : ruet_oj- Published: Oct. 27, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
0.0
NACVE-2025-12682
The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible fo... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
5.9
MEDIUMCVE-2025-12695
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.... Read more
Affected Products :- Published: Nov. 04, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
7.8
HIGHCVE-2025-62801
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts that run fastmc... Read more
Affected Products : fastmcp- Published: Oct. 28, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Injection
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64136
A cross-site request forgery (CSRF) vulnerability in Jenkins Themis Plugin 1.4.1 and earlier allows attackers to connect to an attacker-specified HTTP server.... Read more
Affected Products : themis- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Cross-Site Request Forgery
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64137
A missing permission check in Jenkins Themis Plugin 1.4.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified HTTP server.... Read more
Affected Products : themis- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.9
MEDIUMCVE-2025-62782
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on ... Read more
Affected Products : inventorygui- Published: Oct. 27, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64138
A cross-site request forgery (CSRF) vulnerability in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL.... Read more
Affected Products : start_windocks_container- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Cross-Site Request Forgery
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64139
A missing permission check in Jenkins Start Windocks Containers Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL.... Read more
Affected Products : start_windocks_container- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64141
A cross-site request forgery (CSRF) vulnerability in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.... Read more
Affected Products : nexus_task_runner- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Cross-Site Request Forgery
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64142
A missing permission check in Jenkins Nexus Task Runner Plugin 0.9.2 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.... Read more
Affected Products : nexus_task_runner- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64143
Jenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file s... Read more
Affected Products : openshift_pipeline- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64145
Jenkins ByteGuard Build Actions Plugin 1.0 does not mask API tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : byteguard_build_actions- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64144
Jenkins ByteGuard Build Actions Plugin 1.0 stores API tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.... Read more
Affected Products : byteguard_build_actions- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Misconfiguration
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64146
Jenkins Curseforge Publisher Plugin 1.0 stores API Keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.... Read more
Affected Products : curseforge_publisher- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64147
Jenkins Curseforge Publisher Plugin 1.0 does not mask API Keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.... Read more
Affected Products : curseforge_publisher- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Information Disclosure
 
 - 
                                
                                
4.3
MEDIUMCVE-2025-64148
A missing permission check in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.... Read more
Affected Products : publish_to_bitbucket- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Authorization
 
 - 
                                
                                
5.4
MEDIUMCVE-2025-64149
A cross-site request forgery (CSRF) vulnerability in Jenkins Publish to Bitbucket Plugin 0.4 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentia... Read more
Affected Products : publish_to_bitbucket- Published: Oct. 29, 2025
 - Modified: Nov. 04, 2025
 - Vuln Type: Cross-Site Request Forgery