Vulnerabilities (CVE)

Total 400174 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-54547 2026-06-17 N/A 5.3 MEDIUM
On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
CVE-2025-54546 2026-06-17 N/A 7.5 HIGH
On affected platforms, restricted users could use SSH port forwarding to access host-internal services
CVE-2025-54545 2026-06-17 N/A 7.8 HIGH
On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges.
CVE-2025-54544 1 Opensolution 1 Quick.cms 2026-06-17 N/A 4.8 MEDIUM
QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVE-2025-54543 1 Opensolution 1 Quick.cms 2026-06-17 N/A 4.8 MEDIUM
QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVE-2025-54542 1 Opensolution 1 Quick.cms 2026-06-17 N/A 5.5 MEDIUM
QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVE-2025-54541 1 Opensolution 1 Quick.cms 2026-06-17 N/A 4.3 MEDIUM
QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVE-2025-54540 1 Opensolution 1 Quick.cms 2026-06-17 N/A 6.1 MEDIUM
QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
CVE-2025-54539 1 Apache 1 Activemq Nms Amqp 2026-06-17 N/A 9.8 CRITICAL
A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization logic present in the client to craft responses that may lead to arbitrary code execution on the client side. Although version 2.1.0 introduced a mechanism to restrict deserialization via allow/deny lists, the protection was found to be bypassable under certain conditions. In line with Microsoft’s deprecation of binary serialization in .NET 9, the project is evaluating the removal of .NET binary serialization support from the NMS API entirely in future releases. Mitigation and Recommendations: Users are strongly encouraged to upgrade to version 2.4.0 or later, which resolves the issue. Additionally, projects depending on NMS-AMQP should migrate away from .NET binary serialization as part of a long-term hardening strategy.
CVE-2025-54538 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command
CVE-2025-54537 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.5 MEDIUM
In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots
CVE-2025-54536 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint
CVE-2025-54535 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.8 MEDIUM
In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms
CVE-2025-54534 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.8 MEDIUM
In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page
CVE-2025-54533 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration
CVE-2025-54532 1 Jetbrains 1 Teamcity 2026-06-17 N/A 4.3 MEDIUM
In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies
CVE-2025-54531 1 Jetbrains 1 Teamcity 2026-06-17 N/A 7.7 HIGH
In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
CVE-2025-54530 1 Jetbrains 1 Teamcity 2026-06-17 N/A 7.5 HIGH
In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
CVE-2025-54529 1 Jetbrains 1 Teamcity 2026-06-17 N/A 3.7 LOW
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
CVE-2025-54528 1 Jetbrains 1 Teamcity 2026-06-17 N/A 5.4 MEDIUM
In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow