In Apache Airflow versions from 3.0.0 up to but not including 3.0.5 a medium severity vulnerability CVE-2025-54941 was detected. This vulnerability allows a UI user to redirect the example DAG via the example_dag_decorator parameter to a malicious server and execute code on a worker, when example DAGs are enabled in production or similar DAG code is copied. To fix this vulnerability, users should upgrade to Airflow version 3.0.5 or later. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-54941.
Read more Data AnalyticsIn Apache Airflow versions 3.0.0 through 3.1.0 inclusive a medium severity vulnerability CVE-2025-62402 was detected. This vulnerability allows API users via the /api/v2/dagReports endpoint to execute DAG Python code in the context of the API server if the API-server is deployed in an environment where DAG files are accessible. To fix this vulnerability, users should upgrade to Apache Airflow version 3.1.1 or later. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-62402.
Read more Data AnalyticsIn Liferay Portal versions 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP versions 7.4.0 through 7.4.3.111, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 a medium severity vulnerability CVE-2025-62276 was detected. This vulnerability allows local users to access downloaded files via the browser’s cache due to an incorrect Cache-Control header configuration. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62276.
Read more CMSIn Liferay Portal versions 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP versions 7.4.0 through 7.4.3.111, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92 a medium severity vulnerability CVE-2025-62275 was detected. This vulnerability allows remote attackers to view images in blog entries without proper authorization by exploiting a missing permission check via a crafted URL. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62275.
Read more CMSIn Liferay Portal versions 7.4.3.35 through 7.4.3.111 and Liferay DXP versions 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 U35 through U92 a medium severity vulnerability CVE-2025-62267 was detected. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML via crafted payloads in a user’s First Name, Middle Name, or Last Name fields, leading to multiple cross-site scripting (XSS) issues. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62267.
Read more CMSIn Nagios XI versions prior to 2024R1.1 a medium severity vulnerability CVE-2024-13992 was detected. This vulnerability allows remote attackers to execute arbitrary JavaScript in a victim’s browser via a crafted link that targets the “missing page” (404) page, due to improper validation or escaping of user-supplied input in `page-missing.php`. To address this issue, users should upgrade Nagios XI to version 2024R1.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13992.
Read more MonitoringIn Liferay Portal versions 7.4.3.8 through 7.4.3.111, and Liferay DXP versions 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, Liferay DXP 7.4 U4 through U92 a high severity vulnerability CVE-2025-62264 was detected. This vulnerability allows remote attackers to inject arbitrary web scripts or HTML via the `_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_selectedLanguageId` parameter, leading to a reflected cross-site scripting (XSS) issue. To address this issue, users should upgrade Liferay Portal to version 7.4.3.112 and Liferay DXP to version 2024.Q1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62264.
Read more CMSIn Rancher Manager versions prior to 2.11.7 and 2.12.3 a medium severity vulnerability CVE-2023-32199 was detected. This issue allows users to retain administrative access to clusters even after a custom GlobalRole or its binding has been removed, provided the role included wildcard * permissions for resources or non-resource URLs. To fix this issue, users should upgrade to Rancher Manager versions 2.11.7 or 2.12.3 or later. For more details, visit https://avd.aquasec.com/nvd/2023/cve-2023-32199.
In Rancher Manager versions 2.9.0 through 2.12.2 a medium severity vulnerability CVE-2024-58269 was detected. This vulnerability allows sensitive information — including secret data, cluster import URLs, and registration tokens — to be exposed to any entity with access to Rancher audit logs. To fix this vulnerability, users should upgrade to version 2.12.3 or later. For more details, visit https://avd.aquasec.com/nvd/2024/cve-2024-58269.
Read more Developer Tools