In Zabbix versions 6.0.38 through 6.0.40, 7.0.9 through 7.0.16, 7.2.3 through 7.2.10, and 7.4.0 a low severity vulnerability CVE-2025-27236 was identified. A regular Zabbix user could search other users in their user group via the Zabbix API by selecting fields the user does not have access to view. This allows data-mining of some field values the user does not have access to. To address this issue, users should upgrade Zabbix to versions 6.0.41, 7.0.17, 7.2.11, or 7.4.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27236.
Read more MonitoringIn Zabbix Agent and Agent 2 on Windows versions 6.0.0 through 6.0.40, 7.0.0 through 7.0.17, 7.2.0 through 7.2.11, and 7.4.0 through 7.4.1 a high severity vulnerability CVE-2025-27237 was detected. The OpenSSL configuration file is loaded from a path writable by low-privileged users, allowing malicious modification and potential local privilege escalation by injecting a DLL. To address this issue, users should upgrade Zabbix to versions 6.0.41, 7.0.18, 7.2.12, or 7.4.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27237.
Read more MonitoringIn Zabbix versions 6.0.0 through 6.0.40, 7.0.0 through 7.0.17, 7.2.0 through 7.2.11, and 7.4.0 through 7.4.1 a medium severity vulnerability CVE-2025-49641 was detected. A regular Zabbix user with no permission to the Monitoring → Problems view is still able to call the problem.view.refresh action and retrieve a list of active problems. To address this issue, users should upgrade Zabbix to versions 6.0.41, 7.0.18, 7.2.12, or 7.4.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49641.
Read more MonitoringIn Rancher Manager versions 2.9.0 through 2.9.11, 2.10.0 through 2.10.9, 2.11.0 through 2.11.5, and 2.12.0 through 2.12.1 a high severity vulnerability CVE-2024-58267 was detected. The SAML authentication mechanism used by the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be exploited to steal Rancher authentication tokens, allowing attackers to potentially gain unauthorized access. To address this issue, users should upgrade Rancher Manager to versions 2.9.12, 2.10.10, 2.11.6, 2.12.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58267.
Read more Developer ToolsIn Rancher Manager versions 2.9.0 through 2.9.11, 2.10.0 through 2.10.9, 2.11.0 through 2.11.5, and 2.12.0 through 2.12.1 a high severity vulnerability CVE-2024-58260 was detected. A missing server-side validation on the .username field allows users with update permissions on other User resources to cause denial of access for targeted accounts, potentially impacting system availability and user access. To address this issue, users should upgrade Rancher Manager to versions 2.9.12, 2.10.10, 2.11.6, 2.12.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58260.
Read more Developer ToolsIn Redis versions 8.2.1 and below a high severity vulnerability CVE-2025-49844 was detected. Authenticated users can use a specially crafted Lua script to manipulate the garbage collector, triggering a use-after-free condition that may lead to remote code execution. This issue affects all Redis versions with Lua scripting enabled. To address this issue, users should upgrade Redis to version 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49844.
Read more DatabaseIn Redis versions 8.2.1 and below a medium severity vulnerability CVE-2025-46819 was detected. Authenticated users can use specially crafted Lua scripts to read out-of-bounds data or crash the server, leading to denial of service (DoS). This issue affects all Redis versions with Lua scripting enabled. To address this issue, users should upgrade Redis to version 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-46819.
Read more DatabaseIn Rancher Manager versions 2.9.0 through 2.9.11, 2.10.0 through 2.10.9, 2.11.0 through 2.11.5, and 2.12.0 through 2.12.1 a medium severity vulnerability CVE-2025-54468 was detected. The /meta/proxy endpoint may send Impersonate-Extra-* headers to external entities, such as amazonaws.com. These headers can contain identifiable or sensitive information, including email addresses. To address this issue, users should upgrade Rancher Manager to versions 2.9.12, 2.10.10, 2.11.6, 2.12.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-54468.
Read more Developer ToolsIn Liferay Portal versions 7.4.0 through 7.4.3.111 and older unsupported versions, and Liferay DXP versions 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92, and older unsupported versions a medium severity vulnerability CVE-2025-43824 was detected. The Profile widget uses a user’s name in the “Content-Disposition” header, which allows remote authenticated users to change the file extension when a vCard file is downloaded. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112, and Liferay DXP to versions 2024.Q2.0, 2024.Q1.1, 2023.Q4.6, or 2023.Q3.9. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43824.
Read more CMS