461
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
New
|
CWE-862
Missing Authorization
|
CVE-2025-24461
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
462
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
New
|
CWE-863
Incorrect Authorization
|
CVE-2025-24460
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
463
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-24459
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
464
|
- |
|
-
|
-
|
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-24458
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
465
|
- |
|
-
|
-
|
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-24457
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
466
|
- |
|
-
|
-
|
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-24456
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
467
|
- |
|
-
|
-
|
WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 of the WeGIA application. The vu…
New
|
CWE-601
Open Redirect
|
CVE-2025-24020
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
468
|
- |
|
-
|
-
|
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the filemanager to delete any file owned by the user runn…
New
|
CWE-22
Path Traversal
|
CVE-2025-24019
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
469
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in anyroad.com AnyRoad allows Cross Site Request Forgery. This issue affects AnyRoad: from n/a through 1.3.2.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-23996
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
470
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatebud Estatebud – Properties & Listings allows Stored XSS. This issue affects Estatebud – Pro…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-23994
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|