In Redis versions 2.6 to 7.4.2 a medium severity vulnerability CVE-2025-21605 was detected. This vulnerability allows unauthenticated clients to trigger unbounded growth of output buffers, leading to memory exhaustion or service crashes, due to Redis not limiting output buffers for unauthenticated clients by default and repeated “NOAUTH” responses filling memory. To address this issue, users should upgrade Redis to versions 7.4.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-21605.
Read more DatabaseIn Upsell Funnel Builder for WooCommerce plugin for WordPress versions up to and including 3.0.0 a medium severity vulnerability CVE-2025-3743 was detected. This vulnerability allows unauthenticated attackers to manipulate the product ID and discount field associated with any order bump, enabling them to arbitrarily update the product and discount when adding it to the cart. To address this issue, users should upgrade Upsell Funnel Builder for WooCommerce plugin to versions 3.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3743.
Read more CMSIn Mayosis Core plugin for WordPress versions up to and including 5.4.1 a high severity vulnerability CVE-2025-1565 was detected. This vulnerability allows attackers to read the contents of arbitrary files on the server, potentially exposing sensitive information. To address this issue, users should upgrade Mayosis Core plugin to versions 5.4.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1565.
Read more CMSIn Grafana XY Chart plugin versions 11.6.0 prior to 11.6.0+security-01, 11.5.0 prior to 11.5.3+security-01, 11.4.0 prior to 11.4.3+security-01, 11.3.0 prior to 11.3.5+security-01 and 11.2.0 prior to 11.2.8+security-01 a medium severity vulnerability CVE-2025-2703 was detected. This DOM-based XSS issue allows a user with Editor permissions to modify a panel and execute arbitrary JavaScript. To address this issue, users should upgrade Grafana XY Chart plugin to versions 1.6.0+security-01, 11.5.3+security-01, 11.4.3+security-01, 11.3.5+security-01 and 11.2.8+security-01. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2703.
Read more Data AnalyticsIn Mattermost versions 10.4.x ≤ 10.4.2, 10.5.x ≤ 10.5.0 and 9.11.x ≤ 9.11.10 a low severity vulnerability CVE-2025-41423 was detected. This issue allows any user or attacker to delete posts created by the Playbooks bot through the `/plugins/playbooks/api/v0/signal/keywords/ignore-thread` API endpoint, even without channel access or proper permissions. To address this issue, users should upgrade Mattermost to versions 10.6.0, 10.4.3, 10.5.1, 9.11.11 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-41423.
Read more CommunicationIn GitLab EE/CE versions from 16.6 before 16.9.7, 17.10 before 17.10.5 and 17.11 before 17.11.1 a high severity vulnerability CVE-2025-1908 was discovered. This issue could allow an attacker to track users’ browsing activities, potentially leading to full account takeover. To address this issue, users should upgrade GitLab EE/CE to versions 16.9.7, 17.10.5 or 17.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1908.
Read more Developer ToolsIn GitLab CE/EE versions from 16.7 before 17.9.7, 17.10 before 17.10.5 and 17.11 before 17.11.1 a medium severity vulnerability CVE-2025-0639 was discovered. This issue affects service availability through the issue preview feature. To address this issue, users should upgrade GitLab CE/EE to versions 17.9.7, 17.10.5 or 17.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0639.
Read more Developer ToolsIn GitLab EE versions from 17.7 prior to 17.9.7, 17.10 prior to 17.10.5 and 17.11 prior to 17.11.1 a medium severity vulnerability CVE-2024-12244 was discovered. This issue in access controls may allow users to view restricted project information even when related features are disabled. To address this issue, users should upgrade GitLab EE to versions 17.9.7, 17.10.5 or 17.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12244.
Read more Developer ToolsIn Klarna Checkout for WooCommerce plugin for WordPress versions prior to 2.13.5 a medium severity vulnerability CVE-2024-13925 was detected. This vulnerability allows unauthenticated attackers to flood log files using an exposed WooCommerce Ajax endpoint, rapidly consuming disk space and potentially filling the entire disk. To address this issue, users should upgrade Klarna Checkout for WooCommerce plugin to versions 2.13.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13925.
Read more CMS