In Liferay Portal versions 7.3.2 through 7.4.3.111, and Liferay DXP 7.3 GA through update 35, 7.4 GA through update 92, 2023.Q3.1 through 2023.Q3.8, and 2023.Q4.0 through 2023.Q4.5 a medium severity vulnerability CVE-2025-43830 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload in a form with a rich text type field. Users should update Liferay Portal to 7.4.3.112 and Liferay DXP to 7.3 update 36, 7.4.Q1.1, 2023.Q3.9, or 2023.Q4.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43830.
Read more CMSIn Liferay Portal versions 7.4.3.18 through 7.4.3.111, and Liferay DXP 7.4 update 18 through update 92, 2023.Q3.1 through 2023.Q3.8, and 2023.Q4.0 through 2023.Q4.5 a medium severity vulnerability CVE-2025-43829 was detected. This vulnerability allows remote attackers to inject arbitrary web script or HTML via a crafted payload in a Commerce diagram SVG file. Users should update Liferay Portal to 7.4.3.112 and Liferay DXP to 7.3 update 36, 7.4.Q1.1, 2023.Q3.9, or 2023.Q4.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43829.
Read more CMSIn Mastodon versions 4.2.27 through 4.2.x, 4.3.0 through 4.3.14, and 4.4.0 through 4.4.6 a medium severity vulnerability CVE-2025-62176 was detected. The streaming server serves public timeline events to clients with valid tokens even if they lack the read:statuses scope, allowing limited access to new public posts. To address this issue, users should upgrade Mastodon to versions 4.2.27, 4.3.14, or 4.4.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62176.
Read more CommunicationIn Mastodon versions 4.2.27 through 4.2.x, 4.3.0 through 4.3.14, and 4.4.0 through 4.4.6 a medium severity vulnerability CVE-2025-62175 was detected. Disabling or suspending user accounts does not disconnect them from the streaming API, allowing continued access to real-time updates. To address this issue, users should upgrade Mastodon to versions 4.2.27, 4.3.14, or 4.4.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62175.
Read more CommunicationIn Mastodon versions 4.2.27 through 4.2.x, 4.3.0 through 4.3.14, and 4.4.0 through 4.4.6 a low severity vulnerability CVE-2025-62174 was detected. Active sessions and access tokens are not revoked when a user’s password is reset via the command-line interface, allowing continued access to the account. To address this issue, users should upgrade Mastodon to versions 4.2.27, 4.3.14, or 4.4.6 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-62174.
Read more CommunicationIn Spring Framework versions 6.2.0 through 6.2.11, 6.1.0 through 6.1.23, and 5.3.0 through 5.3.45 a medium severity vulnerability CVE-2025-41254 was detected. STOMP over WebSocket applications may allow an attacker to send unauthorized messages. To address this issue, users should upgrade Spring Framework to versions 6.2.12, 6.1.24, or 5.3.46 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-41254.
Read more Application DevelopmentIn Strapi versions 5.0.0 through 5.5.1 a high severity vulnerability CVE-2024-56143 was detected. The lookup operator in the document service does not properly sanitize query parameters for private fields, allowing an attacker to access sensitive information such as admin passwords and reset tokens. To address this issue, users should upgrade Strapi to version 5.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-56143.
Read more Application DevelopmentIn Mattermost versions 10.5.x through 10.5.10 and 10.11.x through 10.11.2 a low severity vulnerability CVE-2025-10545 was detected. Improper validation of guest user permissions allows attackers to add any team members to private channels via the /api/v4/channels/{channel_id}/members endpoint. To address this issue, users should upgrade to Mattermost versions 10.5.11, 10.11.3, or 10.12.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-10545.
Read more CommunicationIn Apache Spark versions before 3.4.4, 3.5.2, and 4.0.0 a medium severity vulnerability CVE-2025-55039 was detected. When spark.network.crypto.enabled is true but spark.network.crypto.cipher is not explicitly configured, Spark defaults to AES in CTR mode (AES/CTR/NoPadding), which provides encryption without authentication. This allows a man-in-the-middle attacker to modify encrypted RPC traffic undetected, potentially compromising heartbeat messages or application data and affecting the integrity of Spark workflows. To address this issue, users should upgrade Apache Spark to 3.4.4, 3.5.2, or 4.0.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-55039.
Read more Data Analytics