Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-01-21 CVE-2025-21552 Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security).
network
low complexity
6.5
2025-01-21 CVE-2025-24020 Open Redirect vulnerability in Wegia
WeGIA is a Web manager for charitable institutions.
network
low complexity
wegia CWE-601
6.1
2025-01-21 CVE-2025-24457 Information Exposure Through Log Files vulnerability in Jetbrains Youtrack
In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs
local
low complexity
jetbrains CWE-532
5.5
2025-01-21 CVE-2025-24459 Cross-site Scripting vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page
network
low complexity
jetbrains CWE-79
6.1
2025-01-21 CVE-2025-24460 Incorrect Authorization vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool
network
low complexity
jetbrains CWE-863
4.3
2025-01-21 CVE-2025-24461 Missing Authorization vulnerability in Jetbrains Teamcity 2024.12.1
In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint
network
low complexity
jetbrains CWE-862
6.5
2025-01-21 CVE-2025-24011 Information Exposure Through Discrepancy vulnerability in Umbraco CMS
Umbraco is a free and open source .NET content management system.
network
low complexity
umbraco CWE-203
5.3
2025-01-21 CVE-2025-24012 Cross-site Scripting vulnerability in Umbraco CMS
Umbraco is a free and open source .NET content management system.
network
low complexity
umbraco CWE-79
5.4
2025-01-21 CVE-2024-57940 Infinite Loop vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: exfat: fix the infinite loop in exfat_readdir() If the file system is corrupted so that a cluster is linked to itself in the cluster chain, and there is an unused directory entry in the cluster, 'dentry' will not be incremented, causing condition 'dentry < max_dentries' unable to prevent an infinite loop. This infinite loop causes s_lock not to be released, and other tasks will hang, such as exfat_sync_fs(). This commit stops traversing the cluster chain when there is unused directory entry in the cluster to avoid this infinite loop.
local
low complexity
linux CWE-835
5.5
2025-01-21 CVE-2024-57944 NULL Pointer Dereference vulnerability in Linux Kernel
In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: Add NULL check in ads1298_init devm_kasprintf() can return a NULL pointer on failure.
local
low complexity
linux CWE-476
5.5