2251
|
- |
|
-
|
-
|
An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via th…
|
-
|
CVE-2024-55504
|
2025-01-22 04:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2252
|
- |
|
-
|
-
|
SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.
|
-
|
CVE-2024-54795
|
2025-01-22 04:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2253
|
- |
|
-
|
-
|
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
|
-
|
CVE-2024-54794
|
2025-01-22 04:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2254
|
- |
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside…
|
-
|
CVE-2024-54792
|
2025-01-22 04:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2255
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
|
CWE-862
Missing Authorization
|
CVE-2025-24461
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2256
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
|
CWE-863
Incorrect Authorization
|
CVE-2025-24460
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2257
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
|
CWE-79
Cross-site Scripting
|
CVE-2025-24459
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2258
|
- |
|
-
|
-
|
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-24458
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2259
|
- |
|
-
|
-
|
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-24457
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2260
|
- |
|
-
|
-
|
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-24456
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|