In the Broken Link Notifier plugin for WordPress, all versions up to and including 1.3.0 a high severity vulnerability CVE-2025-6838 was detected. This vulnerability allows attackers to inject malicious input into exported CSV files via broken links. To fix this issue, users should upgrade the plugin to version 1.3.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6838.
Read more CMSIn the WPBookit plugin for WordPress, all versions up to and including 1.0.4 a critical severity vulnerability CVE-2025-6058 was detected. This vulnerability allows unauthenticated attackers to upload arbitrary files to the affected site’s server, potentially leading to remote code execution. To fix this issue, users should upgrade the plugin to version 1.0.5. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6058.
Read more CMSIn Ansible versions up to 4.50.3 a medium severity vulnerability CVE-2025-53862 was detected. This vulnerability allows attackers to access three API endpoints that return verbose responses, potentially exposing sensitive information. To fix this issue, users should upgrade Ansible to version 4.52.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53862.
Read more IT Business ManagementIn Ansible version 2.x a low severity vulnerability CVE‑2025‑53861 was detected. This vulnerability allows attackers to intercept session data or hijack user sessions by exploiting insecure cookies transmitted over unencrypted connections. To fix this issue, users should upgrade Ansible to version 4.52.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53861.
Read more IT Business ManagementIn Apache HTTP Server versions up to 2.4.63 a medium severity vulnerability CVE-2025-49812 was detected. This vulnerability allows attackers to hijack active HTTP sessions by exploiting a misconfigured TLS upgrade path, potentially gaining unauthorized access to user data or actions. To fix this issue, users should upgrade Apache HTTP Server to version 2.4.64. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49812.
Read more Application DevelopmentIn Apache HTTP Server versions from 2.4.26 up to 2.4.63 a medium severity vulnerability CVE-2025-49630 was detected. This vulnerability allows attackers to cause a denial of service by triggering an assertion failure in the mod_proxy_http2 module. To fix this issue, users should upgrade Apache HTTP Server to version 2.4.64. For more information, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49630.
Read more Application DevelopmentIn Apache HTTP Server versions from 2.4.35 up to 2.4.63 a medium severity vulnerability CVE-2025-23048 was detected. This vulnerability allows attackers to bypass access control by exploiting TLS session resumption in certain mod_ssl configurations. To fix this issue, users should upgrade Apache HTTP Server to version 2.4.64. For more information, visit https://nvd.nist.gov/vuln/detail/CVE-2025-23048.
Read more Application DevelopmentIn GitLab CE/EE versions from 17.11 up to 17.11.6, 18.0.4, and 18.1.2 a high severity vulnerability CVE-2025-6948 was detected. This vulnerability allows attackers to perform actions on behalf of other users by injecting malicious content. To fix this issue, users should upgrade GitLab to versions 17.11.6, 18.0.4, or 18.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6948.
Read more Developer ToolsIn GitLab EE versions from 18.0 up to 18.0.4 and 18.1.2 a medium severity vulnerability CVE-2025-4972 was detected. This vulnerability allows attackers with invitation privileges to bypass group-level user invitation restrictions by manipulating the group invitation functionality. To fix this issue, users should upgrade GitLab EE to versions 18.0.4 or 18.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4972.
Read more Developer Tools