CVE Database

52637+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2025-53676
6.5 MEDIUM

Jenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controller, where it can be …

Jul 9, 2025
CVE-2025-53675
6.5 MEDIUM

Jenkins Warrior Framework Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users …

Jul 9, 2025
CVE-2025-53674
5.3 MEDIUM

Jenkins Sensedia Api Platform tools Plugin 1.0 does not mask the Sensedia API Manager integration token on the global configuration form, increasing the potential for …

Jul 9, 2025
CVE-2025-53673
6.5 MEDIUM

Jenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration file on the Jenkins controller, where …

Jul 9, 2025
CVE-2025-53672
6.5 MEDIUM

Jenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controller, where it can be …

Jul 9, 2025
CVE-2025-53671
6.5 MEDIUM

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job configuration form, increasing the …

Jul 9, 2025
CVE-2025-53670
6.5 MEDIUM

Jenkins Nouvola DiveCloud Plugin 1.08 and earlier stores DiveCloud API Keys and Credentials Encryption Keys unencrypted in job config.xml files on the Jenkins controller, where …

Jul 9, 2025
CVE-2025-53669
4.3 MEDIUM

Jenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential for attackers to …

Jul 9, 2025
CVE-2025-53668
6.5 MEDIUM

Jenkins VAddy Plugin 1.2.8 and earlier stores Vaddy API Auth Keys unencrypted in job config.xml files on the Jenkins controller, where they can be viewed …

Jul 9, 2025
CVE-2025-53667
5.3 MEDIUM

Jenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potential for attackers to …

Jul 9, 2025
CVE-2025-53666
6.5 MEDIUM

Jenkins Dead Man's Snitch Plugin 0.1 stores Dead Man's Snitch tokens unencrypted in job config.xml files on the Jenkins controller, where they can be viewed …

Jul 9, 2025
CVE-2025-53665
4.3 MEDIUM

Jenkins Apica Loadtest Plugin 1.10 and earlier does not mask Apica Loadtest LTP authentication tokens displayed on the job configuration form, increasing the potential for …

Jul 9, 2025
CVE-2025-53664
6.5 MEDIUM

Jenkins Apica Loadtest Plugin 1.10 and earlier stores Apica Loadtest LTP authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can …

Jul 9, 2025
CVE-2025-53663
6.5 MEDIUM

Jenkins IBM Cloud DevOps Plugin 2.0.16 and earlier stores SonarQube authentication tokens unencrypted in job config.xml files on the Jenkins controller, where they can be …

Jul 9, 2025
CVE-2025-53662
6.5 MEDIUM

Jenkins IFTTT Build Notifier Plugin 1.2 and earlier stores IFTTT Maker Channel Keys unencrypted in job config.xml files on the Jenkins controller, where they can …

Jul 9, 2025
CVE-2025-53661
4.3 MEDIUM

Jenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing the potential for …

Jul 9, 2025
CVE-2025-53660
4.3 MEDIUM

Jenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, increasing the potential for …

Jul 9, 2025
CVE-2025-53659
6.5 MEDIUM

Jenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins controller, where they can …

Jul 9, 2025
CVE-2025-53658
5.4 MEDIUM

Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability …

Jul 9, 2025
CVE-2025-53657
4.3 MEDIUM

Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, …

Jul 9, 2025
CVE-2025-53656
6.5 MEDIUM

Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins …

Jul 9, 2025
CVE-2025-53655
5.3 MEDIUM

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to …

Jul 9, 2025
CVE-2025-53654
6.5 MEDIUM

Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller, where it can …

Jul 9, 2025
CVE-2025-53653
4.3 MEDIUM

Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they …

Jul 9, 2025
CVE-2025-53651
6.3 MEDIUM

Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, …

Jul 9, 2025
CVE-2025-49604
5.4 MEDIUM

For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on 2025/07/03. In the …

Jul 9, 2025
CVE-2025-44526
6.5 MEDIUM

Realtek RTL8762EKF-EVB RTL8762E SDK V1.4.0 was discovered to utilize insufficient permission checks on critical fields within Bluetooth Low Energy (BLE) data packets. This issue allows …

Jul 9, 2025
CVE-2025-7204
6.5 MEDIUM

In ConnectWise PSA versions older than 2025.9, a vulnerability exists where authenticated users could gain access to sensitive user information. Specific API requests were found …

Jul 9, 2025
CVE-2025-2670
4.3 MEDIUM

IBM OpenPages 9.0 is vulnerable to information disclosure of sensitive information due to a weaker than expected security for certain REST end points related to …

Jul 9, 2025
CVE-2025-1112
4.3 MEDIUM

IBM OpenPages with Watson 8.3 and 9.0 could allow an authenticated user to obtain sensitive information that should only be available to privileged users.

Jul 9, 2025
CVE-2025-38264
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: sanitize request list handling Validate the request in nvme_tcp_handle_r2t() to ensure it's not part …

Jul 9, 2025
CVE-2025-38263
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bcache: fix NULL pointer in cache_set_flush() 1. LINE#1794 - LINE#1887 is some codes about function …

Jul 9, 2025
CVE-2025-38262
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tty: serial: uartlite: register uart driver in init When two instances of uart devices are …

Jul 9, 2025
CVE-2025-38261
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: riscv: save the SR_SUM status over switches When threads/tasks are switched we need to ensure …

Jul 9, 2025
CVE-2025-38260
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: handle csum tree error with rescue=ibadroots correctly [BUG] There is syzbot based reproducer that …

Jul 9, 2025
CVE-2025-38258
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: free old damon_sysfs_scheme_filter->memcg_path on write memcg_path_store() assigns a newly allocated memory buffer to filter->memcg_path, …

Jul 9, 2025
CVE-2025-38256
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: io_uring/rsrc: fix folio unpinning syzbot complains about an unmapping failure: [ 108.070381][ T14] kernel BUG …

Jul 9, 2025
CVE-2025-38255
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: lib/group_cpus: fix NULL pointer dereference from group_cpus_evenly() While testing null_blk with configfs, echo 0 > …

Jul 9, 2025
CVE-2025-38254
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Add sanity checks for drm_edid_raw() When EDID is retrieved via drm_edid_raw(), it doesn't guarantee …

Jul 9, 2025
CVE-2025-38253
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix crash in wacom_aes_battery_handler() Commit fd2a9b29dc9c ("HID: wacom: Remove AES power_supply after extended …

Jul 9, 2025
CVE-2025-38252
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: cxl/ras: Fix CPER handler device confusion By inspection, cxl_cper_handle_prot_err() is making a series of fragile …

Jul 9, 2025
CVE-2025-38251
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: atm: clip: prevent NULL deref in clip_push() Blamed commit missed that vcc_destroy_socket() calls clip_push() with …

Jul 9, 2025
CVE-2025-38247
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: userns and mnt_idmap leak in open_tree_attr(2) Once want_mount_setattr() has returned a positive, it does require …

Jul 9, 2025
CVE-2025-38246
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: bnxt: properly flush XDP redirect lists We encountered following crash when testing a XDP_REDIRECT feature …

Jul 9, 2025
CVE-2025-38244
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential deadlock when reconnecting channels Fix cifs_signal_cifsd_for_reconnect() to take the correct lock …

Jul 9, 2025
CVE-2025-38243
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix invalid inode pointer dereferences during log replay In a few places where we …

Jul 9, 2025
CVE-2025-38242
4.7 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm: userfaultfd: fix race of userfaultfd_move and swap cache This commit fixes two kinds of …

Jul 9, 2025
CVE-2025-38241
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/shmem, swap: fix softlockup with mTHP swapin Following softlockup can be easily reproduced on my …

Jul 9, 2025
CVE-2025-38238
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: scsi: fnic: Fix crash in fnic_wq_cmpl_handler when FDMI times out When both the RHBA and …

Jul 9, 2025
CVE-2025-27028
6.8 MEDIUM

The Linux deprivileged user vpuser in Radiflow iSAP Smart Collector (CentOS 7 - VSAP 1.20) can read the entire file system content, including files belonging …

Jul 9, 2025

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.