Latest CVE Feed
-
9.8
CRITICALCVE-2025-28412
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28411
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28410
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-28409
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28408
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2025-28407
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28406
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28405
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
7.2
HIGHCVE-2025-28403
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-28402
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-28401
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
6.7
MEDIUMCVE-2025-28400
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method... Read more
Affected Products : ruoyi- Published: Apr. 07, 2025
- Modified: Apr. 09, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-3372
A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The ex... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3371
A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotel... Read more
- Published: Apr. 07, 2025
- Modified: May. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-3248
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.... Read more
Affected Products : langflow- Actively Exploited
- Published: Apr. 07, 2025
- Modified: May. 07, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-32014
estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Misconfiguration
-
4.8
MEDIUMCVE-2025-31476
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as ... Read more
- Published: Apr. 07, 2025
- Modified: Sep. 04, 2025
- Vuln Type: Cross-Site Scripting
-
5.5
MEDIUMCVE-2025-31475
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where the addOrUpdate function, used for applying custom texts, did not properly validate input. This allowed an attacker wit... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2025-31138
tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js prior to 1.20.1, where user-controlled inputs for element dimensions (width and height) were not properly validated. This allowed an attacker ... Read more
Affected Products :- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Misconfiguration
-
6.5
MEDIUMCVE-2025-30373
Graylog is a free and open log management platform. Starting with 6.1, HTTP Inputs can be configured to check if a specified header is present and has a specified value to authenticate HTTP-based ingestion. Unfortunately, even though in cases of a missing... Read more
Affected Products : graylog- Published: Apr. 07, 2025
- Modified: Apr. 08, 2025
- Vuln Type: Authentication