7.6
CVE-2025-23369 - Improper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofβ¦
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signature spoofing for unauthorized internal users. Instances not utilizing SAML single sign-on or where the attacker is not already an existing user were not impacted. This vuβ¦
4.8
CVE-2025-24020 - WeGIA Open Redirect vulnerability
WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 of the WeGIA application. The vulnerability allows the `nextPage` parameter to be manipulated, redirecting authenticated users to arβ¦
6.8
CVE-2025-22150 - Undici Uses Insufficiently Random Values
Undici is an HTTP/1.1 client. Starting in version 4.5.0 and prior to versions 5.28.5, 6.21.1, and 7.2.3, undici uses `Math.random()` to choose the boundary for a multipart/form-data request. It is known that the output of `Math.random()` can be predicted if several of its generated values are knownβ¦
7.1
CVE-2025-24019 - YesWiki vulnerable to authenticated arbitrary file deletion
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the filemanager to delete any file owned by the user running the FastCGI Process Manager (FPM) on the host without any limitation on the filesystem's scope. β¦
6.5
CVE-2025-24461 -
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
4.3
CVE-2025-24460 -
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projectsβ names in the agent pool
4.6
CVE-2025-24459 -
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
7.1
CVE-2025-24458 -
In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration
5.5
CVE-2025-24457 -
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
6.7
CVE-2025-24456 -
In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping