In Directus versions 9.12.0 and above a medium severity vulnerability CVE-2025-53889 was detected. This vulnerability allows attackers to execute manual trigger Flows without authentication or proper access rights, potentially performing unauthorized actions on behalf of a user. To address this issue, users should upgrade Directus to version 11.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53889.
Read more CMSIn Directus versions 9.0.0 and above a medium severity vulnerability CVE-2025-53887 was detected. This vulnerability allows attackers to obtain the exact Directus version via the unauthenticated /server/specs/oas endpoint, potentially aiding in targeted exploitation using known vulnerabilities. To address this issue, users should upgrade Directus to version 11.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53887.
Read more CMSIn Directus versions 9.0.0 and above a medium severity vulnerability CVE-2025-53886 was detected. This vulnerability allows malicious administrators to hijack user sessions by accessing sensitive data such as access and refresh tokens logged during Flow WebHook executions. To address this issue, users should upgrade Directus to version 11.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53886.
Read more CMSIn Directus versions 9.0.0 and above a medium severity vulnerability CVE-2025-53885 was detected. This vulnerability allows malicious administrators to log sensitive user data using the “Log to Console” operation within Flows triggered by user CRUD events. To address this issue, users should upgrade Directus to version 11.9.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53885.
Read more CMSIn Grafana versions prior to 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 and 12.0.1+security-01 a medium severity vulnerability CVE-2025-3415 was detected. This vulnerability allows users with Viewer permission to access the Grafana Alerting DingDing integration, which was not properly protected. To address this issue, users should upgrade Grafana to versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01, 11.4.5+security-01, 11.5.5+security-01, 11.6.2+security-01 or 12.0.1+security-01. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3415.
Read more CMSIn SQLite versions prior to 3.50.2 a high severity vulnerability CVE-2025-6965 was detected. This vulnerability, caused by integer truncation when the number of aggregate terms exceeds the number of available columns, may lead to memory corruption. To address this issue, users should upgrade SQLite to versions 3.50.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6965.
Read more DatabaseIn ZITADEL versions from 2.53.0 up to but not including 4.0.0-rc.2, 3.3.2, 2.71.13 and 2.70.14 a high severity vulnerability CVE-2025-53895 was detected. This vulnerability allows any authenticated user to hijack sessions and impersonate other users by updating arbitrary sessions using only the session ID, due to missing authorization checks in the session management API. To address this issue, users should upgrade ZITADEL to versions 4.0.0-rc.2, 3.3.2, 2.71.13 or 2.70.14. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53895.
Read more Developer ToolsIn Oracle MySQL Client versions 8.0.0 through 8.0.42, 8.4.0 through 8.4.5 and 9.0.0 through 9.3.0 a low severity vulnerability CVE-2025-50081 was detected in the mysqldump component. This vulnerability allows high-privileged attackers with network access and requiring user interaction to perform unauthorized updates, inserts, deletes, or read access to MySQL Client-accessible data. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-50081.
Read more DatabaseIn Oracle MySQL Server versions 8.0.0 through 8.0.42 a medium severity vulnerability CVE-2025-53023 was detected in the Replication component. This vulnerability allows high-privileged attackers with network access to cause a hang or repeatable crash of the MySQL Server, resulting in denial-of-service (DoS). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53023.
Read more Database