Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-68925 is a medium severity vulnerability in the samrocketman jervis library used for Job DSL plugin scripts and Jenkins pipeline libraries. Versions prior to 2.2 do not properly verify that the JWT header specifies the expected cryptographic algorithm "alg":"RS256". This improper verification (CWE-347) can allow attackers to bypass signature validation, potentially enabling unauthorized code execution or pipeline manipulation. The vulnerability is remotely exploitable without authentication or user interaction, with a CVSS score of 6.9. It affects Jenkins environments using vulnerable jervis versions, which are common in CI/CD pipelines. The flaw is fixed in version 2.2. European organizations relying on Jenkins automation and shared pipeline libraries should prioritize upgrading to mitigate risk. Join the discussion | CVE Database V5 | 01/13/2026, 19:30:05 UTC Added: 01/13/2026, 19:41:31 UTC |
CVE-2025-68704 is a high-severity vulnerability affecting versions of the Jervis library prior to 2.2. The issue stems from the use of java.util. Random(), which is not cryptographically secure, leading to insufficient randomness in critical operations. This weakness can enable timing attacks that compromise the integrity of Jenkins pipeline scripts relying on Jervis. The vulnerability does not require authentication or user interaction but has a high attack complexity, limiting exploitation ease. European organizations using Jenkins with Jervis versions below 2.2 are at risk, especially those in sectors relying heavily on CI/CD pipelines. The vulnerability has no known exploits in the wild yet, but patching to version 2. Join the discussion | CVE Database V5 | 01/13/2026, 19:29:06 UTC Added: 01/13/2026, 19:41:31 UTC |
CVE-2025-68703 is a high-severity vulnerability in the samrocketman jervis library used for Job DSL plugin scripts and Jenkins pipeline libraries. Versions prior to 2.2 derive the encryption salt from a sha256 hash of the passphrase, causing identical keys to be generated for the same password across encryption operations. This inadequate encryption strength (CWE-326) can lead to predictable encryption keys, weakening confidentiality protections. The vulnerability requires no authentication or user interaction and can be exploited remotely. It has a CVSS 4.0 score of 8.7, indicating high severity. The issue is fixed in version 2.2 of jervis. Join the discussion | CVE Database V5 | 01/13/2026, 19:27:33 UTC Added: 01/13/2026, 19:41:31 UTC |
0 CVE-2025-68702 is a high-severity vulnerability in the samrocketman Jervis library, used for Job DSL plugin scripts and Jenkins shared pipeline libraries. The issue arises from incorrect padding in cryptographic operations where padLeft(32, '0') is used instead of padLeft(64, '0') to handle SHA-256 hashes, which are 32 bytes or 64 hex characters long. This improper padding leads to the use of a broken or risky cryptographic algorithm (CWE-327), potentially weakening the security of cryptographic functions within affected Jenkins pipelines. The vulnerability affects all Jervis versions prior to 2.2 and does not require authentication or user interaction to exploit, with a CVSS 4.0 score of 8.7 indicating high severity. Although no known exploits are currently in the wild, the flaw could allow attackers to compromise the integrity of pipeline scripts or related secrets. The issue is fixed in version 2.2 of Jervis. Join the discussion | CVE Database V5 | 01/13/2026, 19:26:32 UTC Added: 01/13/2026, 19:41:31 UTC |
0 CVE-2025-68701 is a high-severity cryptographic vulnerability in the Jervis library used for Jenkins Job DSL and shared pipeline scripts. Versions prior to 2.2 use a deterministic AES initialization vector (IV) derived from a passphrase, which weakens encryption by making ciphertext patterns predictable and susceptible to cryptanalysis. This flaw allows attackers to potentially recover sensitive data or compromise the confidentiality of encrypted information without requiring authentication or user interaction. The vulnerability has a CVSS 4.0 base score of 8.7, indicating a network-exploitable issue with high impact on confidentiality. The issue is fixed in Jervis version 2.2. European organizations relying on Jenkins automation with Jervis versions before 2. Join the discussion | CVE Database V5 | 01/13/2026, 19:21:30 UTC Added: 01/13/2026, 19:41:31 UTC |
CVE-2025-68931 is a high-severity vulnerability affecting versions of the samrocketman jervis library prior to 2.2. The issue arises from the use of AES encryption in CBC mode with PKCS5 padding without proper authentication, making it vulnerable to padding oracle attacks and ciphertext manipulation. This improper authentication flaw (CWE-287) combined with weak cryptographic usage (CWE-327) allows attackers to decrypt or alter encrypted data without authorization. The vulnerability requires no authentication or user interaction and can be exploited remotely, posing a significant risk to confidentiality and integrity. The flaw is fixed in version 2.2 of jervis. European organizations using Jenkins pipelines or Job DSL scripts that incorporate jervis versions before 2.2 could face data compromise or pipeline manipulation. Mitigation involves upgrading to jervis 2. Join the discussion | CVE Database V5 | 01/13/2026, 19:17:26 UTC Added: 01/13/2026, 19:26:32 UTC |
0 Jervis is a library for Job DSL plugin scripts and shared Jenkins pipeline libraries. Prior to 2.2, Jervis uses PKCS1Encoding which is vulnerable to Bleichenbacher padding oracle attacks. Modern systems should use OAEP (Optimal Asymmetric Encryption Padding). This vulnerability is fixed in 2.2. Join the discussion | CVE Database V5 | 01/13/2026, 19:16:01 UTC Added: 01/13/2026, 19:26:32 UTC |
Showing 1 to 7 of 7 results