CVE tracker
389 subscribers
5.53K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2025-28402 - Ruyi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28402
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28403 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28403
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28405 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28405
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28406 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28406
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28407 - Apache RUoYi Unauthenticated Privilege Escalation Vulnerability

CVE ID : CVE-2025-28407
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28408 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28408
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28409 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28409
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28410 - "RUoYi Privilege Escalation Vulnerability"

CVE ID : CVE-2025-28410
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28411 - RUoYi RCE

CVE ID : CVE-2025-28411
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28412 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28412
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-28413 - RUoYi Privilege Escalation Vulnerability

CVE ID : CVE-2025-28413
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3373 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3373
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3374 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3374
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3424 - IntelliSpace Portal .NET Remoting Unauthenticated File Disclosure

CVE ID : CVE-2025-3424
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific .NET Remoting URLs derived from information enumerated in the client-side configuration files. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3425 - "IntelliSpace Portal .NET Remoting Deserialization Remote Code Execution"

CVE ID : CVE-2025-3425
Published : April 7, 2025, 4:15 p.m. | 1 hour, 5 minutes ago
Description : The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is dangerous as it can potentially lead to remote code execution using deserialization. This issue affects IntelliSpace Portal: 12 and prior.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3375 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3375
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3376 - PCMan FTP Server CONF Command Handler Buffer Overflow Vulnerability

CVE ID : CVE-2025-3376
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3426 - "IntelliSpace Portal Unprotected Binary Reversibility and Hardcoded Credentials"

CVE ID : CVE-2025-3426
Published : April 7, 2025, 5:15 p.m. | 4 hours, 5 minutes ago
Description : We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer the application to gain insights into its internal workings, which can potentially lead to the discovery of sensitive information, business logic flaws, and other vulnerabilities. Utilizing this flaw, the attacker was able to identify the Hardcoded credentials from PortalUsersDatabase.dll, which contains .NET remoting definition. Inside the namespace PortalUsersDatabase, the class Users contains the functions CreateAdmin and CreateService that are used to initialize accounts in the Portal service. Both CreateAdmin and CreateService functions contain a hardcoded encrypted password along with its respective salt that are set with the function SetInitialPasswordAndSalt. This issue affects IntelliSpace Portal: 12 and prior; Advanced Visualization Workspace: 15.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2024-38797 - EDK2 HashPeImageByType Out-of-Bounds Read Vulnerability

CVE ID : CVE-2024-38797
Published : April 7, 2025, 6:15 p.m. | 3 hours, 5 minutes ago
Description : EDK2 contains a vulnerability in the HashPeImageByType(). A user may cause a read out of bounds when a corrupted data pointer and length are sent via an adjecent network. A successful exploit of this vulnerability may lead to a loss of Integrity and/or Availability.
Severity: 4.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3377 - PCMan FTP Server Buffer Overflow Vulnerability

CVE ID : CVE-2025-3377
Published : April 7, 2025, 6:15 p.m. | 3 hours, 5 minutes ago
Description : A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component ENC Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2025-3378 - PCMan FTP Server EPRT Command Handler Buffer Overflow

CVE ID : CVE-2025-3378
Published : April 7, 2025, 6:15 p.m. | 3 hours, 5 minutes ago
Description : A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...