2281
|
- |
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside…
|
-
|
CVE-2024-54792
|
2025-01-22 04:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2282
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
|
CWE-862
Missing Authorization
|
CVE-2025-24461
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2283
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
|
CWE-863
Incorrect Authorization
|
CVE-2025-24460
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2284
|
- |
|
-
|
-
|
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
|
CWE-79
Cross-site Scripting
|
CVE-2025-24459
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2285
|
- |
|
-
|
-
|
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2025-24458
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2286
|
- |
|
-
|
-
|
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-24457
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2287
|
- |
|
-
|
-
|
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-24456
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2288
|
- |
|
-
|
-
|
WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 of the WeGIA application. The vu…
|
CWE-601
Open Redirect
|
CVE-2025-24020
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2289
|
- |
|
-
|
-
|
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the filemanager to delete any file owned by the user runn…
|
CWE-22
Path Traversal
|
CVE-2025-24019
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2290
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in anyroad.com AnyRoad allows Cross Site Request Forgery. This issue affects AnyRoad: from n/a through 1.3.2.
|
CWE-352
Origin Validation Error
|
CVE-2025-23996
|
2025-01-22 03:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|