In Next.js App Router versions from 15.3.0 to before 15.3.3 and Vercel CLI from 41.4.1 to 42.2.0 a medium severity vulnerability CVE-2025-49005 was detected. This vulnerability allows attackers to trick the server into saving the wrong version of a page in the cache, so other users might see broken or incorrect content when they visit the site. To fix this issue, users should upgrade to Next.js version 15.3.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49005.
Read more Application DevelopmentIn Zulip Server versions from 2.0.0-rc1 to 10.4 a medium severity vulnerability CVE-2025-52559 was detected. This vulnerability allows attackers to inject and execute malicious scripts in users’ browsers by exploiting unsanitized topic or channel names in the /digest/ preview, potentially leading to data theft or session hijacking. To fix this issue, users should upgrade to Zulip Server version 10.4. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-52559.
Read more CommunicationIn the PayMaster for WooCommerce plugin for WordPress, all versions up to and including 0.4.31 a high severity vulnerability CVE-2025-6729 was detected. This vulnerability allows attackers to send unauthorized requests from the server to internal or external systems, potentially accessing or modifying sensitive information. Currently there is not fix for this vulnerability. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-6729.
Read more CMSIn the JKDEVKIT plugin for WordPress all versions up to and including 1.9.4 a critical severity vulnerability CVE-2025-2932 was detected. This vulnerability allows authenticated attackers with Subscriber-level access or higher to delete arbitrary files on the server due to insufficient file path validation in the ‘font_upload_handler’ function. Currently there is not fix for this vulnerability. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2932.
Read more CMSIn Sentry versions prior to 25.5.0 a high severity vulnerability CVE-2025-53099 was detected. This vulnerability allows attackers with a malicious OAuth application to exploit a race condition and improper authorization code handling during the OAuth exchange process, enabling them to maintain persistent access to a user’s account even after the application is de-authorized. To address this issue users must upgrade to version 25.5.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53099.
Read more MonitoringIn Apache Guacamole versions 1.5.5 and earlier a high severity vulnerability CVE-2024-35164 was detected. This vulnerability allows a malicious user with access to a text-based connection (such as SSH) to exploit improperly validated console codes, potentially leading to arbitrary code execution with the privileges of the running guacd process. To fix this issue, users should upgrade to version 1.6.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-35164.
In Ansible Automation Platform’s EDA component, all versions before 1.1.10 a high severity vulnerability CVE-2025-49520 was detected. This vulnerability allows attackers to execute arbitrary system commands on the EDA worker by injecting malicious arguments into the git ls-remote command, potentially leading to sensitive data exposure, such as Kubernetes or OpenShift service account tokens, and full cluster compromise. To fix this issue, users should upgrade Ansible Automation Platform’s EDA component to version 1.1.11. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-49520.
Read more IT Business ManagementIn AAPanel version 7.0.7 a critical severity vulnerability CVE-2024-42922 was detected. This vulnerability allows attackers to perform OS command injection, potentially leading to full system compromise. To address this issue users must upgrade to a patched version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-42922.
Read more Application DevelopmentIn Apache Cassandra versions 4.0.0 through 4.0.15, 4.1.0 through 4.1.7, and 5.0.0 through 5.0.2
a high severity vulnerability CVE-2025-24860 was detected. This vulnerability allows users to access unauthorized datacenters or IP/CIDR groups and modify their own permissions via DCL statements. To fix this issue, users should upgrade to versions 4.0.16, 4.1.8, or 5.0.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24860.