In Kanboard versions 1.2.45 and prior a medium severity vulnerability CVE-2025-52576 was detected. This vulnerability allows attackers to enumerate valid usernames and bypass IP-based brute-force protection mechanisms such as Fail2Ban or CAPTCHA by abusing trusted HTTP headers and analyzing login behavior. This puts user accounts at higher risk of credential stuffing and brute-force attacks. To address this issue, users should upgrade Kanboard to version 1.2.46. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-52576.
Read more Project ManagementIn Umbraco versions 10.0.0 through 10.8.10 and 13.0.0 through 13.9.1 a medium severity vulnerability CVE-2025-49147 was detected. This vulnerability allows unauthenticated attackers to access limited information about the configured password requirements via an anonymous endpoint, which could aid brute-force attacks. To address this issue, users should upgrade Umbraco to versions 10.8.11 or 13.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49147.
Read more CMSIn Discourse versions prior to 3.4.6 (stable) and 3.5.0.beta8-dev (tests-passed) a medium severity vulnerability CVE-2025-49845 was detected. This vulnerability allows users to continue viewing their own whisper posts even after losing group-based permission to view such content. To address this issue, users should upgrade Discourse to versions 3.4.6 or later (stable), 3.5.0.beta8-dev (tests-passed). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49845.
Read more CommunicationIn Gogs versions prior to 0.13.3 a critical severity vulnerability CVE-2024-56731 was detected. This vulnerability allows unprivileged users to delete files under the .git directory and execute arbitrary commands with the privileges of the configured RUN_USER, enabling remote command execution and unauthorized modification of other users’ code hosted on the same instance. To address this issue, users should upgrade to versions 0.13.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-56731.
Read more Developer ToolsIn Kanboard versions prior to 1.2.46 a high severity vulnerability CVE-2025-52560 was detected. This vulnerability allows attackers to craft malicious password reset links by exploiting an unvalidated Host header when the application_url configuration is unset, potentially leading to account takeover. To address this issue, users should upgrade Kanboard to versions 1.2.46 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-52560.
Read more Project ManagementIn Kubernetes kube-apiserver versions 1.32.0 up to 1.32.5 and 1.33.0 up to 1.33.1 a high severity vulnerability CVE-2025-4563 was detected. This vulnerability allows compromised nodes to bypass authorization checks during pod creation and access unauthorized dynamic resources, potentially leading to privilege escalation. To address this issue, users should upgrade Kubernetes kube-apiserver to versions 1.32.6 or later, 1.33.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4563.
Read more Developer ToolsIn MLflow versions prior to 3.1.0 a medium severity vulnerability CVE-2025-52967 was detected. This vulnerability is caused by the lack of `gateway_path` validation in the `gateway_proxy_handler`, which may allow attackers to manipulate request routing or access unintended resources. To address this issue, users should upgrade MLflow to versions 3.1.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-52967.
Read more Data AnalyticsIn Moodle versions 3.x through 3.11.18 a medium severity vulnerability CVE-2025-53021 was detected. This vulnerability allows unauthenticated attackers to hijack user sessions by obtaining and reusing the sesskey parameter within the OAuth2 login flow, resulting in full account takeover, and it affects only unsupported versions maintained by the developer. To address this issue, users should upgrade Moodle to versions 3.11.18 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53021.
Read more EducationalIn GitLab EE versions from 16.0 before 16.3.6, from 16.4 before 16.4.2 and from 16.5 before 16.5.1 a low severity vulnerability CVE-2023-5600 was detected. This vulnerability allows unauthorized users to gain arbitrary access to the titles of private specific references through the service-desk custom email template. To address this issue, users should upgrade GitLab EE to versions 16.3.6, 16.4.2 or 16.5.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-5600.
Read more Developer Tools