In Flask-AppBuilder versions prior to 4.8.1 a medium severity vulnerability CVE-2025-58065 was detected. This vulnerability allows enabled users to reset their password and generate JWT tokens even after being disabled on the authentication provider, when Flask-AppBuilder is configured with OAuth, LDAP, or other non-database authentication methods. To address this issue, users should upgrade Flask-AppBuilder to version 4.8.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-58065.
Read more Application DevelopmentIn GitLab CE/EE versions from 15.1 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 a medium severity vulnerability CVE-2025-6769 was detected. This vulnerability allows authenticated users to view administrator-only maintenance notes by accessing runner details through specific interfaces. To address this issue, users should upgrade GitLab CE/EE to versions 18.1.6, 18.2.6, or 18.3.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6769.
Read more Developer ToolsIn GitLab CE/EE versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 a medium severity vulnerability CVE-2025-6454 was detected. This vulnerability allows authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences. To address this issue, users should upgrade GitLab CE/EE to versions 18.1.6, 18.2.6, or 18.3.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6454.
Read more Developer ToolsIn Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier a high severity vulnerability CVE-2025-54236 was detected. This vulnerability is caused by improper input validation and allows attackers to achieve session takeover, with a high impact on confidentiality and integrity. To address this issue, users should upgrade Adobe Commerce to version 2.4.10. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-54236.
Read more E-commerceIn Liferay Portal versions 7.4.3.73 through 7.4.3.128 and Liferay DXP versions 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 73 through update 92 a medium severity vulnerability CVE-2025-43783 was detected. This vulnerability allows attackers to inject arbitrary web script or HTML via the /c/portal/comment/discussion/get_editor path. To address this issue, users should upgrade Liferay Portal to version 7.4.3.129 or later, and Liferay DXP to versions 2024.Q3.2, 2024.Q2.14, or 2024.Q1.13. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43783.
In Liferay Portal versions 7.4.0 through 7.4.3.124 and Liferay DXP versions 2024.Q2.0 through 2024.Q2.8, 2024.Q1.1 through 2024.Q1.12, and 7.4 GA through update 92 a midium severity vulnerability CVE-2025-43784 was detected. This vulnerability allows guest users to obtain object entries information via the API Builder. To address this issue, users should upgrade Liferay Portal to version 7.4.3.125 or later, and Liferay DXP to versions 2024.Q2.9 or 2024.Q1.13. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43784.
Read more CMSIn Liferay Portal versions 7.4.3.45 through 7.4.3.128 and Liferay DXP versions 2024.Q2.0 through 2024.Q2.9, 2024.Q1.1 through 2024.Q1.12, and 7.4 update 45 through update 92 a medium severity vulnerability CVE-2025-43785 was detected. This vulnerability allows attackers to execute arbitrary web script or HTML in the My Workflow Tasks page. To address this issue, users should upgrade Liferay Portal to version 7.4.3.129 or later, and Liferay DXP to versions 2024.Q2.10 or 2024.Q1.13. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43785.
Read more CMSIn GitLab Community Edition and Enterprise Edition all versions prior to 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 a medium severity vulnerability CVE-2025-5101 was detected. This vulnerability allows an authenticated attacker under certain conditions to distribute malicious code that appears harmless in the web interface by exploiting ambiguity between branches and tags during repository imports. To address this issue, users should upgrade GitLab to versions 18.1.5, 18.2.5, 18.3.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5101.
Read more Developer ToolsIn Liferay Portal versions 7.4.0 through 7.4.3.128, and Liferay DXP versions 2024.Q3.0 through 2024.Q3.1, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12, 2023.Q4.0 and 7.4 GA through update 92 a medium severity vulnerability CVE-2025-43786 was detected. This vulnerability allows attackers to determine existent ERC in the application by exploiting the time response. To address this issue, users should upgrade Liferay Portal to version 7.4.3.129, or Liferay DXP to versions 2024.Q1.13, 2024.Q3.2 or 2024.Q4.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-43786.
Read more CMS