Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2025-67638

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67637

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67636

A missing permission check in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers with View/Read permission to view encrypted password values in views.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67635

Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not properly close HTTP-based CLI connections when the connection stream becomes corrupted, allowing unauthenticated attackers to cause a denial of service.

PUBLISHED
Vendor
Jenkins Project
Product
Jenkins
Provider severity
HIGH
Conflicts
0

CVE-2025-67634

The CISA Software Acquisition Guide Supplier Response Web Tool before 2025-12-11 was vulnerable to cross-site scripting via text fields. If an attacker could convince a user to import a specially-crafted JSON file, the Tool would load JavaScript from the file into the page. The JavaScript would execute in the context of the user's browser when the user submits the page (clicks 'Next').

PUBLISHED
Vendor
CISA
Product
Software Acquisition Guide Tool
Provider severity
MEDIUM
Conflicts
1

CVE-2025-67633

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brownbagmarketing Greenhouse Job Board greenhouse-job-board allows DOM-Based XSS.This issue affects Greenhouse Job Board: from n/a through <= 2.7.3.

PUBLISHED
Vendor
brownbagmarketing
Product
Greenhouse Job Board
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67632

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in The Plugin Factory Google AdSense for Responsive Design – GARD google-adsense-for-responsive-design-gard allows DOM-Based XSS.This issue affects Google AdSense for Responsive Design – GARD: from n/a through <= 2.23.

PUBLISHED
Vendor
The Plugin Factory
Product
Google AdSense for Responsive Design – GARD
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67631

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ecommerce Platforms Gift Hunt gift-hunt allows Stored XSS.This issue affects Gift Hunt: from n/a through <= 2.0.2.

PUBLISHED
Vendor
Ecommerce Platforms
Product
Gift Hunt
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67630

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webheadcoder WH Tweaks wh-tweaks allows Stored XSS.This issue affects WH Tweaks: from n/a through <= 1.0.2.

PUBLISHED
Vendor
webheadcoder
Product
WH Tweaks
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67629

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Basticom Basticom Framework basticom-framework allows Stored XSS.This issue affects Basticom Framework: from n/a through <= 1.5.2.

PUBLISHED
Vendor
Basticom
Product
Basticom Framework
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67628

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AMP-MODE Review Disclaimer review-disclaimer allows Stored XSS.This issue affects Review Disclaimer: from n/a through <= 2.0.3.

PUBLISHED
Vendor
AMP-MODE
Product
Review Disclaimer
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67627

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in TouchOfTech Draft Notify draft-notify allows Stored XSS.This issue affects Draft Notify: from n/a through <= 1.5.

PUBLISHED
Vendor
TouchOfTech
Product
Draft Notify
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67626

Cross-Site Request Forgery (CSRF) vulnerability in Angel Costa WP SEO Search wp-seo-search allows Cross Site Request Forgery.This issue affects WP SEO Search: from n/a through <= 1.1.

PUBLISHED
Vendor
Angel Costa
Product
WP SEO Search
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67625

Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forgery.This issue affects Trade Runner: from n/a through <= 3.14.

PUBLISHED
Vendor
tmtraderunner
Product
Trade Runner
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67624

Missing Authorization vulnerability in Arya Dhiratara Optimize More! – Images optimize-more-images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Optimize More! – Images: from n/a through <= 1.1.3.

PUBLISHED
Vendor
Arya Dhiratara
Product
Optimize More! – Images
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67623

Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6Storage Rentals: from n/a through <= 2.22.0.

PUBLISHED
Vendor
6Storage
Product
6Storage Rentals
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67622

Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS.This issue affects Evergreen Post Tweeter: from n/a through <= 1.8.9.

PUBLISHED
Vendor
titopandub
Product
Evergreen Post Tweeter
Provider severity
HIGH
Conflicts
0

CVE-2025-67621

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Workflow eight-day-week-print-workflow allows Retrieve Embedded Sensitive Data.This issue affects Eight Day Week Print Workflow: from n/a through <= 1.2.5.

PUBLISHED
Vendor
10up
Product
Eight Day Week Print Workflow
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10.

PUBLISHED
Vendor
CleverSoft
Product
Anon
Provider severity
HIGH
Conflicts
0

CVE-2025-6762

A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the file /admin/login of the component HTTP Header Handler. The manipulation of the argument Host leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

PUBLISHED
Vendor
diyhi
Product
bbs
Provider severity
MEDIUM
Conflicts
1

CVE-2025-67619

Deserialization of Untrusted Data vulnerability in designthemes Kids Heaven kids-world allows Object Injection.This issue affects Kids Heaven: from n/a through <= 3.2.

PUBLISHED
Vendor
designthemes
Product
Kids Heaven
Provider severity
HIGH
Conflicts
0

CVE-2025-67618

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ArtstudioWorks Brookside allows Reflected XSS.This issue affects Brookside: from n/a through 1.4.

PUBLISHED
Vendor
ArtstudioWorks
Product
Brookside
Provider severity
HIGH
Conflicts
0

CVE-2025-67617

Deserialization of Untrusted Data vulnerability in themeton Consult Aid consultaid allows Object Injection.This issue affects Consult Aid: from n/a through <= 1.4.3.

PUBLISHED
Vendor
themeton
Product
Consult Aid
Provider severity
CRITICAL
Conflicts
0

CVE-2025-67616

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in BZOTheme Mella mella allows PHP Local File Inclusion.This issue affects Mella: from n/a through <= 1.2.29.

PUBLISHED
Vendor
BZOTheme
Product
Mella
Provider severity
HIGH
Conflicts
0

CVE-2025-67615

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in bslthemes Myour myour allows PHP Local File Inclusion.This issue affects Myour: from n/a through <= 1.5.1.

PUBLISHED
Vendor
bslthemes
Product
Myour
Provider severity
HIGH
Conflicts
0

CVE-2025-67614

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheNa thena allows Reflected XSS.This issue affects TheNa: from n/a through <= 1.5.5.

PUBLISHED
Vendor
foreverpinetree
Product
TheNa
Provider severity
HIGH
Conflicts
0

CVE-2025-6761

A vulnerability was found in Kingdee Cloud-Starry-Sky Enterprise Edition 6.x/7.x/8.x/9.0. It has been rated as critical. Affected by this issue is the function plugin.buildMobilePopHtml of the file \k3\o2o\bos\webapp\action\DynamicForm 4 Action.class of the component Freemarker Engine. The manipulation leads to improper neutralization of special elements used in a template engine. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended

PUBLISHED
Vendor
Kingdee
Product
Cloud-Starry-Sky Enterprise Edition
Provider severity
HIGH, MEDIUM
Conflicts
2

CVE-2025-67604

A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager 6.4 all versions may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests caus

PUBLISHED
Vendor
Fortinet, Fortinet
Product
FortiAnalyzer, FortiManager
Provider severity
MEDIUM
Conflicts
1

CVE-2025-67603

A Improper Authorization vulnerability in Foomuuri llows arbitrary users to influence the firewall configuration.This issue affects Foomuuri: from ? before 0.31.

PUBLISHED
Vendor
https://github.com/FoobarOy/
Product
Foomuuri
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67601

A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts.

PUBLISHED
Vendor
SUSE
Product
rancher
Provider severity
HIGH
Conflicts
0

CVE-2025-67599

Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WebToffee eCommerce Marketing Automation: from n/a through <= 2.1.1.

PUBLISHED
Vendor
WebToffee
Product
WebToffee eCommerce Marketing Automation
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67598

Cross-Site Request Forgery (CSRF) vulnerability in PSM Plugins SupportCandy supportcandy allows Cross Site Request Forgery.This issue affects SupportCandy: from n/a through <= 3.4.1.

PUBLISHED
Vendor
PSM Plugins
Product
SupportCandy
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67597

Missing Authorization vulnerability in Shahjahan Jewel Fluent Booking fluent-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Booking: from n/a through <= 1.9.11.

PUBLISHED
Vendor
Shahjahan Jewel
Product
Fluent Booking
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67596

Cross-Site Request Forgery (CSRF) vulnerability in Strategy11 Team Business Directory business-directory-plugin allows Cross Site Request Forgery.This issue affects Business Directory: from n/a through <= 6.4.19.

PUBLISHED
Vendor
Strategy11 Team
Product
Business Directory
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67595

Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Quiz Maker quiz-maker allows Cross Site Request Forgery.This issue affects Quiz Maker: from n/a through <= 6.7.0.82.

PUBLISHED
Vendor
Ays Pro
Product
Quiz Maker
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67594

Authorization Bypass Through User-Controlled Key vulnerability in ThimPress Thim Elementor Kit thim-elementor-kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Thim Elementor Kit: from n/a through <= 1.3.3.

PUBLISHED
Vendor
ThimPress
Product
Thim Elementor Kit
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67593

Cross-Site Request Forgery (CSRF) vulnerability in Stiofan UsersWP userswp allows Cross Site Request Forgery.This issue affects UsersWP: from n/a through <= 1.2.48.

PUBLISHED
Vendor
Stiofan
Product
UsersWP
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67592

Missing Authorization vulnerability in Joe Dolson My Calendar my-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Calendar: from n/a through <= 3.6.16.

PUBLISHED
Vendor
Joe Dolson
Product
My Calendar
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67591

Cross-Site Request Forgery (CSRF) vulnerability in jegtheme JNews Paywall jnews-paywall allows Cross Site Request Forgery.This issue affects JNews Paywall: from n/a through < 12.0.1.

PUBLISHED
Vendor
jegtheme
Product
JNews Paywall
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67590

Cross-Site Request Forgery (CSRF) vulnerability in Rustaurius Ultimate FAQ ultimate-faqs allows Cross Site Request Forgery.This issue affects Ultimate FAQ: from n/a through <= 2.4.3.

PUBLISHED
Vendor
Rustaurius
Product
Ultimate FAQ
Provider severity
MEDIUM
Conflicts
0

CVE-2025-6759

Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Windows Virtual Delivery Agent for CVAD and Citrix DaaS

PUBLISHED
Vendor
Citrix
Product
Windows Virtual Delivery Agent for CVAD and Citrix DaaS
Provider severity
HIGH
Conflicts
0

CVE-2025-67589

Missing Authorization vulnerability in WP Overnight WooCommerce PDF Invoices & Packing Slips woocommerce-pdf-invoices-packing-slips allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WooCommerce PDF Invoices & Packing Slips: from n/a through <= 4.9.1.

PUBLISHED
Vendor
WP Overnight
Product
WooCommerce PDF Invoices & Packing Slips
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67588

Missing Authorization vulnerability in Elementor Elementor Website Builder elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elementor Website Builder: from n/a through <= 3.33.0.

PUBLISHED
Vendor
Elementor
Product
Elementor Website Builder
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67587

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Phishing.This issue affects WP Gravity Forms FreshDesk Plugin: from n/a through <= 1.3.5.

PUBLISHED
Vendor
CRM Perks
Product
WP Gravity Forms FreshDesk Plugin
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67586

Missing Authorization vulnerability in Ronald Huereca Highlight and Share highlight-and-share allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Highlight and Share: from n/a through <= 5.2.0.

PUBLISHED
Vendor
Ronald Huereca
Product
Highlight and Share
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67585

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in flexmls Flexmls® IDX flexmls-idx allows Phishing.This issue affects Flexmls® IDX: from n/a through <= 3.15.7.

PUBLISHED
Vendor
flexmls
Product
Flexmls® IDX
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67584

Missing Authorization vulnerability in rtCamp GoDAM godam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects GoDAM: from n/a through <= 1.4.6.

PUBLISHED
Vendor
rtCamp
Product
GoDAM
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67583

Missing Authorization vulnerability in Foysal Imran IDonate idonate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IDonate: from n/a through <= 2.1.15.

PUBLISHED
Vendor
Foysal Imran
Product
IDonate
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67582

Missing Authorization vulnerability in wbcomdesigns Wbcom Designs lock-my-bp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wbcom Designs: from n/a through <= 2.1.1.

PUBLISHED
Vendor
wbcomdesigns
Product
Wbcom Designs
Provider severity
MEDIUM
Conflicts
0

CVE-2025-67581

Missing Authorization vulnerability in themetechmount TrueBooker truebooker-appointment-booking allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TrueBooker: from n/a through <= 1.1.0.

PUBLISHED
Vendor
themetechmount
Product
TrueBooker
Provider severity
MEDIUM
Conflicts
0