Latest CVE Feed
-
9.8
CRITICALCVE-2025-3375
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exp... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3373
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launc... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3372
A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The ex... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-4497
A vulnerability was found in code-projects Simple Banking System up to 1.0. It has been rated as critical. This issue affects some unknown processing of the component Sign In. The manipulation of the argument password2 leads to buffer overflow. Attacking ... Read more
Affected Products : simple_banking_system- Published: May. 10, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.1
CRITICALCVE-2025-26492
In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources... Read more
Affected Products : teamcity- Published: Feb. 11, 2025
- Modified: May. 16, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-26493
In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab... Read more
Affected Products : teamcity- Published: Feb. 11, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2025-31139
In JetBrains TeamCity before 2025.03 base64 encoded password could be exposed in build log... Read more
Affected Products : teamcity- Published: Mar. 27, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-31140
In JetBrains TeamCity before 2025.03 stored XSS was possible on Cloud Profiles page... Read more
Affected Products : teamcity- Published: Mar. 27, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2025-31141
In JetBrains TeamCity before 2025.03 exception could lead to credential leakage on Cloud Profiles page... Read more
Affected Products : teamcity- Published: Mar. 27, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
6.5
MEDIUMCVE-2025-46432
In JetBrains TeamCity before 2025.03.1 base64-encoded credentials could be exposed in build logs... Read more
Affected Products : teamcity- Published: Apr. 25, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-46433
In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible... Read more
Affected Products : teamcity- Published: Apr. 25, 2025
- Modified: May. 16, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2025-46618
In JetBrains TeamCity before 2025.03.1 stored XSS was possible on Data Directory tab... Read more
Affected Products : teamcity- Published: Apr. 25, 2025
- Modified: May. 16, 2025
- Vuln Type: Cross-Site Scripting
-
7.3
HIGHCVE-2025-20104
Race condition in some Administrative Tools for some Intel(R) Network Adapters package before version 29.4 may allow an authenticated user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Race Condition
-
4.8
MEDIUMCVE-2024-31150
Out-of-bounds read for some Intel(R) Graphics Driver software may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Information Disclosure
-
5.8
MEDIUMCVE-2024-43101
Improper access control for some Intel(R) Data Center GPU Flex Series for Windows driver software before version 31.0.101.4255 may allow an authenticated user to potentially enable denial of service via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
5.0
MEDIUMCVE-2025-20076
Improper access control for some Edge Orchestrator software for Intel(R) Tiber™ Edge Platform may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-20100
Improper access control in the memory controller configurations for some Intel(R) Xeon(R) 6 processor with E-cores may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
8.7
HIGHCVE-2025-24308
Improper input validation in the UEFI firmware error handler for the Intel(R) Server D50DNP and M50FCP may allow a privileged user to potentially enable escalation of privilege via local access.... Read more
Affected Products :- Published: May. 13, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
5.3
MEDIUMCVE-2024-8988
The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the file_download REST API endpoint due to missing validation on a user controlled key. This makes it po... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authorization
-
9.5
CRITICALCVE-2025-47292
Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175bdaf2be0b8102dd198, the `DebateAlternateArgumentsResolver` deserializes a `Cursor`, allowing any classes and which can be controlled by ... Read more
Affected Products :- Published: May. 14, 2025
- Modified: May. 16, 2025
- Vuln Type: Authentication