Total
400174 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-54547 | 2026-06-17 | N/A | 5.3 MEDIUM | ||
| On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired | |||||
| CVE-2025-54546 | 2026-06-17 | N/A | 7.5 HIGH | ||
| On affected platforms, restricted users could use SSH port forwarding to access host-internal services | |||||
| CVE-2025-54545 | 2026-06-17 | N/A | 7.8 HIGH | ||
| On affected platforms, a restricted user could break out of the CLI sandbox to the system shell and elevate their privileges. | |||||
| CVE-2025-54544 | 1 Opensolution | 1 Quick.cms | 2026-06-17 | N/A | 4.8 MEDIUM |
| QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |||||
| CVE-2025-54543 | 1 Opensolution | 1 Quick.cms | 2026-06-17 | N/A | 4.8 MEDIUM |
| QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker with admin privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. By default admin user is not able to add JavaScript into the website. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |||||
| CVE-2025-54542 | 1 Opensolution | 1 Quick.cms | 2026-06-17 | N/A | 5.5 MEDIUM |
| QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser history to obtain the necessary credentials to log in as the user. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |||||
| CVE-2025-54541 | 1 Opensolution | 1 Quick.cms | 2026-06-17 | N/A | 4.3 MEDIUM |
| QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft special website, which when visited by the admin, will automatically send a POST request deleting an article. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |||||
| CVE-2025-54540 | 1 Opensolution | 1 Quick.cms | 2026-06-17 | N/A | 6.1 MEDIUM |
| QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can craft a specially crafted URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.8 was tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |||||
| CVE-2025-54539 | 1 Apache | 1 Activemq Nms Amqp | 2026-06-17 | N/A | 9.8 CRITICAL |
| A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization logic present in the client to craft responses that may lead to arbitrary code execution on the client side. Although version 2.1.0 introduced a mechanism to restrict deserialization via allow/deny lists, the protection was found to be bypassable under certain conditions. In line with Microsoft’s deprecation of binary serialization in .NET 9, the project is evaluating the removal of .NET binary serialization support from the NMS API entirely in future releases. Mitigation and Recommendations: Users are strongly encouraged to upgrade to version 2.4.0 or later, which resolves the issue. Additionally, projects depending on NMS-AMQP should migrate away from .NET binary serialization as part of a long-term hardening strategy. | |||||
| CVE-2025-54538 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.5 MEDIUM |
| In JetBrains TeamCity before 2025.07 password exposure was possible via command line in the "hg pull" command | |||||
| CVE-2025-54537 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.5 MEDIUM |
| In JetBrains TeamCity before 2025.07 user credentials were stored in plain text in memory snapshots | |||||
| CVE-2025-54536 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.4 MEDIUM |
| In JetBrains TeamCity before 2025.07 a CSRF was possible on GraphQL endpoint | |||||
| CVE-2025-54535 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.8 MEDIUM |
| In JetBrains TeamCity before 2025.07 password reset and email verification tokens were using weak hashing algorithms | |||||
| CVE-2025-54534 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.8 MEDIUM |
| In JetBrains TeamCity before 2025.07 reflected XSS was possible on the agentpushPreset page | |||||
| CVE-2025-54533 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via VCS configuration | |||||
| CVE-2025-54532 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 4.3 MEDIUM |
| In JetBrains TeamCity before 2025.07 improper access control allowed disclosure of build settings via snapshot dependencies | |||||
| CVE-2025-54531 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 7.7 HIGH |
| In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows | |||||
| CVE-2025-54530 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 7.5 HIGH |
| In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions | |||||
| CVE-2025-54529 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 3.7 LOW |
| In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration | |||||
| CVE-2025-54528 | 1 Jetbrains | 1 Teamcity | 2026-06-17 | N/A | 5.4 MEDIUM |
| In JetBrains TeamCity before 2025.07 a CSRF was possible in GitHub App connection flow | |||||
