6.9

CVSS4.0

CVE-2025-3376 - PCMan FTP Server CONF Command buffer overflow

A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknown code of the component CONF Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may…

πŸ“… Published: April 7, 2025, 5 p.m. πŸ”„ Last Modified: May 16, 2025, 2:56 p.m.

6.9

CVSS4.0

CVE-2025-3375 - PCMan FTP Server CDUP Command buffer overflow

A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of the component CDUP Command Handler. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and ma…

πŸ“… Published: April 7, 2025, 4:31 p.m. πŸ”„ Last Modified: May 16, 2025, 2:56 p.m.

7.2

CVSS4.0

CVE-2025-3426 - Use of default hardcoded credentials

We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent reverse engineering. Specifically, the app’s code is not obfuscated, and no measures are in place to protect against decompilation, disassembly, or debugging. As a result, attackers can reverse-engineer …

πŸ“… Published: April 7, 2025, 4:23 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

7.3

CVSS4.0

CVE-2025-3425 - Unauthenticated Remote Code Execution via .NET Deserialization

The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the deserialization vulnerability. After analyzing the configuration files, we observed that the server had set the TypeFilterLevel to Full which is d…

πŸ“… Published: April 7, 2025, 4:05 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

6.9

CVSS4.0

CVE-2025-3374 - PCMan FTP Server CCC Command buffer overflow

A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown functionality of the component CCC Command Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and…

πŸ“… Published: April 7, 2025, 4 p.m. πŸ”„ Last Modified: April 23, 2025, 10:33 p.m.

7.7

CVSS4.0

CVE-2025-3424 - 3.2.1 Arbitrary File Read in insecure .NET Remoting TCP Channel

The IntelliSpace portal application utilizes .NET Remoting for its functionality. The vulnerability arises from the exploitation of port 755 through the "Object Marshalling" technique, which allows an attacker to read internal files without any authentication. This is possible by crafting specific …

πŸ“… Published: April 7, 2025, 3:36 p.m. πŸ”„ Last Modified: June 24, 2025, 9:44 a.m.

6.9

CVSS4.0

CVE-2025-3373 - PCMan FTP Server SITE CHMOD Command buffer overflow

A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is an unknown functionality of the component SITE CHMOD Command Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed…

πŸ“… Published: April 7, 2025, 3:31 p.m. πŸ”„ Last Modified: May 16, 2025, 2:56 p.m.

6.9

CVSS4.0

CVE-2025-3372 - PCMan FTP Server MKDIR Command buffer overflow

A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component MKDIR Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and m…

πŸ“… Published: April 7, 2025, 3 p.m. πŸ”„ Last Modified: May 16, 2025, 2:56 p.m.

6.9

CVSS4.0

CVE-2025-32014 - estree-util-value-to-estree allows prototype pollution in generated ESTree

estree-util-value-to-estree converts a JavaScript value to an ESTree expression. When generating an ESTree from a value with a property named __proto__, valueToEstree would generate an object that specifies a prototype instead. This vulnerability is fixed in 3.3.3.

πŸ“… Published: April 7, 2025, 2:56 p.m. πŸ”„ Last Modified: April 8, 2025, 6:14 p.m.

4.8

CVSS3.1

CVE-2025-31476 - tarteaucitron.js allows url scheme injection via unfiltered inputs

tarteaucitron.js is a compliant and accessible cookie banner. A vulnerability was identified in tarteaucitron.js, allowing a user with high privileges (access to the site's source code or a CMS plugin) to enter a URL containing an insecure scheme such as javascript:alert(). Before the fix, URL vali…

πŸ“… Published: April 7, 2025, 2:52 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 5:43 p.m.
Total resulsts: 344154
Page 5481 of 34,416
Β« previous page Β» next page
Filters