CVE-2025-3371 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3371
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3371
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unknown processing of the component DELETE Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3372 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3372
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3372
Published : April 7, 2025, 3:15 p.m. | 2 hours, 4 minutes ago
Description : A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28400 - Apache Struts Privilege Escalation Vulnerability
CVE ID : CVE-2025-28400
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28400
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28401 - "RUoYi Privilege Escalation Vulnerability"
CVE ID : CVE-2025-28401
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28401
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28402 - Ruyi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28402
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28402
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28403 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28403
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28403
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28405 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28405
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28405
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28406 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28406
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28406
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28407 - Apache RUoYi Unauthenticated Privilege Escalation Vulnerability
CVE ID : CVE-2025-28407
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28407
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28408 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28408
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28408
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28409 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28409
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28409
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28410 - "RUoYi Privilege Escalation Vulnerability"
CVE ID : CVE-2025-28410
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28410
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28411 - RUoYi RCE
CVE ID : CVE-2025-28411
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28411
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28412 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28412
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28412
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28413 - RUoYi Privilege Escalation Vulnerability
CVE ID : CVE-2025-28413
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-28413
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3373 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3373
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3373
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3374 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3374
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3374
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3424 - IntelliSpace Portal .NET Remoting Unauthenticated File Disclosure
CVE ID : CVE-2025-3424
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3424
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3425 - "IntelliSpace Portal .NET Remoting Deserialization Remote Code Execution"
CVE ID : CVE-2025-3425
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can potentially lead to remote code execution using deserialization. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3425
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can potentially lead to remote code execution using deserialization. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3375 - PCMan FTP Server Buffer Overflow Vulnerability
CVE ID : CVE-2025-3375
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3375
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3376 - PCMan FTP Server CONF Command Handler Buffer Overflow Vulnerability
CVE ID : CVE-2025-3376
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2025-3376
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...