6.5

CVSS3.1

CVE-2025-68267 -

In JetBrains TeamCity before 2025.11.1 excessive privileges were possible due to storing GitHub personal access token instead of an installation token

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:20 p.m.

5.4

CVSS3.1

CVE-2025-68166 -

In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:20 p.m.

5.4

CVSS3.1

CVE-2025-68165 -

In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:20 p.m.

2.7

CVSS3.1

CVE-2025-68164 -

In JetBrains TeamCity before 2025.11 port enumeration was possible via the Perforce connection test

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:22 p.m.

3.5

CVSS3.1

CVE-2025-68163 -

In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:23 p.m.

2.7

CVSS3.1

CVE-2025-68162 -

In JetBrains TeamCity before 2025.11 maven embedder allowed loading extensions via project configuration

πŸ“… Published: Dec. 16, 2025, 3:27 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:24 p.m.

8.1

CVSS4.0

CVE-2025-14432 - Poly Video - Sensitive Data Might Be Written to Log File

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration c…

πŸ“… Published: Dec. 16, 2025, 3:15 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 7:54 p.m.

5

CVSS3.1

CVE-2025-62329 - HCL DevOps Deploy / HCL Launch is susceptible to an insufficient session expiration vulnerability

HCL DevOps Deploy / HCL Launch is susceptible to a race condition in http-session client-IP binding enforcement which may allow a session to be briefly reused from a new IP address before it is invalidated. This could lead to unauthorized access under certain network conditions.

πŸ“… Published: Dec. 16, 2025, 3:11 p.m. πŸ”„ Last Modified: Jan. 7, 2026, 9:07 p.m.

0.0

CVE-2025-68262 - crypto: zstd - fix double-free in per-CPU stream cleanup

In the Linux kernel, the following vulnerability has been resolved: crypto: zstd - fix double-free in per-CPU stream cleanup The crypto/zstd module has a double-free bug that occurs when multiple tfms are allocated and freed. The issue happens because zstd_streams (per-CPU contexts) are freed in…

πŸ“… Published: Dec. 16, 2025, 2:45 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-14780 - Xiongwei Smart Catering Cloud Platform dish_trade_detail_get sql injection

A vulnerability was detected in Xiongwei Smart Catering Cloud Platform 2.1.6446.28761. The affected element is an unknown function of the file /dishtrade/dish_trade_detail_get. The manipulation of the argument filter results in sql injection. The attack can be executed remotely. The exploit is now …

πŸ“… Published: Dec. 16, 2025, 1:02 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 2566 of 34,919
Β« previous page Β» next page
Filters