In ClickHouse versions 25.7.1.557 a low severity vulnerability CVE-2025-52969 was detected. This vulnerability allows low-privileged users to execute shell commands by querying existing Executable() tables created by higher-privileged users and, if they can influence the script path used by the table engine, potentially escalate privileges and execute unauthorized code in the context of the ClickHouse server. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-52969.
Read more Data AnalyticsIn Gogs versions 0.14.0+dev and prior a medium severity vulnerability CVE-2025-47943 was detected. This vulnerability allows attackers to execute arbitrary JavaScript in the user’s browser via a stored cross-site scripting (XSS) issue caused by the inclusion of a vulnerable pdfjs-1.4.20 component. To address this issue, users should upgrade Gogs to versions 0.13.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-47943.
Read more Developer ToolsIn GitLab EE versions from 16.0 before 16.3.6, from 16.4 before 16.4.2 and from 16.5 before 16.5.1 a low severity vulnerability CVE-2023-5600 was detected. This vulnerability allows unauthorized users to gain arbitrary access to the titles of private specific references through the service-desk custom email template. To address this issue, users should upgrade GitLab EE to versions 16.3.6, 16.4.2 or 16.5.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-5600.
Read more Developer ToolsIn GitLab CE/EE versions from 17.11 before 17.11.4 and 18.0 before 18.0.2 a high severity vulnerability CVE-2025-5121 was detected. This vulnerability allows attackers to apply compliance frameworks to projects outside of the intended compliance framework’s group due to a missing authorization check. To address this issue, users should upgrade GitLab CE/EE to versions 17.11.4 or 18.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-5121.
Read more Developer ToolsIn GitLab EE versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1 a high severity vulnerability CVE-2025-2443 was detected. This vulnerability allows attackers to perform cross-site scripting (XSS) attacks and bypass content security policy (CSP) protections in the user’s browser under specific conditions. To address this issue, users should upgrade GitLab EE to versions 17.9.7, 17.10.5 or 17.11.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-2443.
Read more Developer ToolsIn GitLab EE versions from 17.0 prior to 17.0.6, 17.1 prior to 17.1.4 and 17.2 prior to 17.2.2 a medium severity vulnerability CVE-2024-7586 was detected. This vulnerability allows authentication credentials to be preserved in the audit logs when webhooks are deleted, potentially exposing sensitive information. To address this issue, users should upgrade GitLab EE to versions 17.0.6, 17.1.4 or 17.2.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-7586.
Read more Developer ToolsIn GitLab CE/EE versions from 16.1.0 before 16.11.5, 17.0 before 17.0.3 and 17.1.0 before 17.1.1 a high severity vulnerability CVE-2024-4994 was detected. This vulnerability allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against GitLab’s GraphQL API, enabling the execution of arbitrary GraphQL mutations. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.5, 17.0.3 or 17.1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-4994.
Read more Developer ToolsIn GitLab CE/EE versions from 7.10 before 16.11.5, 17.0 before 17.0.3 and 17.1 before 17.1.1 a medium severity vulnerability CVE-2024-4025 was detected. This vulnerability allows attackers to trigger a Denial of Service (DoS) condition by using a crafted markdown page. To address this issue, users should upgrade GitLab CE/EE to versions 16.11.5, 17.0.3 or 17.1.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-4025.
Read more Developer ToolsIn Mattermost versions 10.5.x ≤ 10.5.5, 9.11.x ≤ 9.11.15, 10.8.x ≤ 10.8.0, 10.7.x ≤ 10.7.2 and 10.6.x ≤ 10.6.5 a critical severity vulnerability CVE-2025-4981 was detected. This vulnerability allows authenticated users to write files to arbitrary locations on the filesystem by uploading archives containing path traversal sequences in filenames, potentially leading to remote code execution. This affects instances where file attachments and content extraction are enabled (default configuration). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4981.
Read more Communication