Latest CVE Feed
-
7.2
HIGHCVE-2025-3426
We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. ... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-3376
A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The expl... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3375
A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exp... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
7.3
HIGHCVE-2025-3425
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server ha... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Misconfiguration
-
7.7
HIGHCVE-2025-3424
The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentica... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 10, 2025
- Vuln Type: Information Disclosure
-
9.8
CRITICALCVE-2025-3374
A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The ... Read more
- Published: Apr. 07, 2025
- Modified: Apr. 23, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3373
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launc... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-28413
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28412
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28411
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28410
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-28409
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28408
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-28407
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28406
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28405
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-28403
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28402
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-28401
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-28400
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization