NA - CVE-2025-49604 - For Realtek AmebaD devices, a heap-based buffer...
For Realtek AmebaD devices, a heap-based buffer overflow was discovered in Ameba-AIoT ameba-arduino-d before version 3.1.9 and ameba-rtos-d before commit c2bfd8216a1cbc19ad2ab5f48f372ecea756d67a on...
NA - CVE-2025-53650 - Jenkins Credentials Binding Plugin...
Jenkins Credentials Binding Plugin 687.v619cb_15e923f and earlier does not properly mask (i.e., replace with asterisks) credentials present in exception error messages that are written to the build...
NA - CVE-2025-53651 - Jenkins HTML Publisher Plugin 425 and earlier...
Jenkins HTML Publisher Plugin 425 and earlier displays log messages that include the absolute paths of files archived during the Publish HTML reports post-build step, exposing information about the...
NA - CVE-2025-53652 - Jenkins Git Parameter Plugin...
Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing attackers with...
NA - CVE-2025-53653 - Jenkins Aqua Security Scanner Plugin 3.2.8 and...
Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with...
NA - CVE-2025-53654 - Jenkins Statistics Gatherer Plugin 2.0.3 and...
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier stores the AWS Secret Key unencrypted in its global configuration file on the Jenkins controller, where it can be viewed by users with access to...
NA - CVE-2025-53655 - Jenkins Statistics Gatherer Plugin 2.0.3 and...
Jenkins Statistics Gatherer Plugin 2.0.3 and earlier does not mask the AWS Secret Key on the global configuration form, increasing the potential for attackers to observe and capture it.
NA - CVE-2025-53656 - Jenkins ReadyAPI Functional Testing Plugin 1.11...
Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier stores SLM License Access Keys, client secrets, and passwords unencrypted in job config.xml files on the Jenkins controller, where they...
NA - CVE-2025-53657 - Jenkins ReadyAPI Functional Testing Plugin 1.11...
Jenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed on the job configuration form, increasing the potential...
NA - CVE-2025-53658 - Jenkins Applitools Eyes Plugin 1.16.5 and...
Jenkins Applitools Eyes Plugin 1.16.5 and earlier does not escape the Applitools URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with...