In Vault Community Edition versions prior to 1.20.3 and Vault Enterprise versions prior to 1.20.3, 1.19.9, 1.18.14 and 1.16.25 a high severity vulnerability CVE-2025-6203 was detected. This vulnerability allows an unauthenticated attacker to cause a denial of service by submitting a specially-crafted complex JSON payload that leads to excessive memory and CPU consumption. To address this issue, users should upgrade Vault Community Edition to versions 1.20.3 or Vault Enterprise to versions 1.20.3, 1.19.9, 1.18.14, 1.16.25 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6203.
Read more SecurityIn Liferay Portal versions 7.4.3.27 through 7.4.3.42, and Liferay DXP versions 2024.Q1.1 through 2024.Q1.20, 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, and 7.4 update 27 through update 42 a high severity vulnerability CVE-2025-3586 was detected. This vulnerability allows an authenticated administrator with the Instance Administrator role to execute arbitrary Groovy scripts (i.e., remote code execution) through the Objects module. To address this issue, users should upgrade Liferay Portal to versions 7.4.3.43 and Liferay DXP to versions 2024.Q2.0 or 2024.Q3.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3586.
Read more CMSIn Mautic versions 4.4.0 through 4.4.16, 5.0.0-alpha through 5.2.7, and 6.0.0-alpha through 6.0.4 a low severity vulnerability CVE-2025-9821 was detected. This vulnerability allows a user with webhook permissions to perform a Server-Side Request Forgery (SSRF) attack by sending webhooks to an unvalidated destination. To address this issue, users should upgrade Mautic to versions 4.4.17, 5.2.8 or 6.0.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9821.
Read more Marketing AutomationIn Rancher Manager versions 2.12.0 through 2.12.0, 2.11.0 through 2.11.4, 2.10.0 through 2.10.8, and 2.9.0 through 2.9.11 a high severity vulnerability CVE-2024-58259 was detected. This vulnerability allows an attacker to cause a Denial of Service (DoS) by sending excessively large payloads to unauthenticated and authenticated API endpoints. To address this issue, users should upgrade Rancher Manager to versions 2.12.1, 2.11.5, 2.10.9 or 2.9.12. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-58259.
Read more Developer ToolsIn Next.js versions before 14.2.31 and from 15.0.0 to before 15.4.5 a medium severity vulnerability CVE-2025-57752 was detected. This vulnerability allows an attacker to access images from API routes that depend on request headers which could be incorrectly cached and served to unauthorized users. To address this issue, users should upgrade Next.js to versions 14.2.31 or 15.4.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-57752.
Read more Application DevelopmentIn Kubernetes versions 1.31.11 and prior, 1.32.7 and prior and 1.33.3 and prior a medium severity vulnerability CVE-2025-5187 was detected. This vulnerability allows an attacker to delete their corresponding node object and then recreate it with modified taints or labels. To address this issue, users should upgradeĀ kube-apiserver binary to versions 1.31.12, 1.32.8, 1.33.4 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5187.
Read more Developer ToolsIn Liferay Portal versions 7.4.0 through 7.4.3.132, and Liferay DXP versions 2025.Q2.0 through 2025.Q2.1, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.0 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13 and 2024.Q1.1 through 2024.Q1.18 a medium severity vulnerability CVE-2025-43773 was detected. This vulnerability allows for improper access through the expandoTableLocalService. To address this issue, users should upgrade Liferay Portal to master branch and Liferay DXP to versions 2025.Q2.1, 2025.Q1.15 or 2024.Q1.19. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43773.
Read more CMSIn Nagios XI versions prior to 2024R1.3.2 a high severity vulnerability CVE-2024-13986 was detected. This vulnerability allows an authenticated attacker to achieve remote code execution by chaining an arbitrary file upload with a path traversal in the Core Config Snapshots interface. To address this issue, users should upgrade Nagios XI to versions 2024R1.3.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13986.
Read more MonitoringIn Next.js versions prior to 14.2.32 and 15.4.7 a medium severity vulnerability CVE-2025-57822 was detected. This vulnerability allows an attacker to perform a Server-Side Request Forgery (SSRF) in self-hosted applications that incorrectly forwarded user-supplied headers. To address this issue, users should upgrade Next.js Middleware to versions 14.2.32 or 15.4.7. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-57822.
Read more Application Development