NA - CVE-2025-25634 - A vulnerability has been found in Tenda AC15...
A vulnerability has been found in Tenda AC15 15.03.05.19 in the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument src leads to stack-based...
NA - CVE-2025-27516 - Jinja is an extensible templating engine. Prior...
Jinja is an extensible templating engine. Prior to 3.1.6, an oversight in how the Jinja sandboxed environment interacts with the |attr filter allows an attacker that controls the content of a...
NA - CVE-2025-27508 - Emissary is a P2P based data-driven workflow...
Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum generation, but it includes or defaults to algorithms that are no longer...
NA - CVE-2025-27622 - Jenkins 2.499 and earlier, LTS 2.492.1 and...
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read...
NA - CVE-2025-27623 - Jenkins 2.499 and earlier, LTS 2.492.1 and...
Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission...
NA - CVE-2025-27624 - A cross-site request forgery (CSRF)...
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.499 and earlier, LTS 2.492.1 and earlier allows attackers to have users toggle their collapsed/expanded status of sidepanel widgets...
NA - CVE-2025-27625 - In Jenkins 2.499 and earlier, LTS 2.492.1 and...
In Jenkins 2.499 and earlier, LTS 2.492.1 and earlier, redirects starting with backslash (`\`) characters are considered safe, allowing attackers to perform phishing attacks by having users go to a...