In Mattermost versions 10.6.x ≤ 10.6.1, 10.5.x ≤ 10.5.2, 10.4.x ≤ 10.4.4 and 9.11.x ≤ 9.11.11 a medium severity vulnerability CVE-2025-3446 was detected. This vulnerability allows authenticated users with permission only to invite non-guest users to add guest users to teams via the API. To address this issue, users should upgrade Mattermost to versions 10.7.0, 10.6.2, 10.5.3, 10.4.5, 9.11.12 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3446.
Read more CommunicationIn Next.js versions prior to 14.2.24 and 15.1.6 a low severity vulnerability CVE-2025-32421 was detected. This race-condition vulnerability in the Pages Router under certain misconfigurations causes normal endpoints to serve `pageProps` data instead of standard HTML. To address this issue, users should upgrade Next.js to versions 15.1.6 or 14.2.24. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-32421.
Read more Application DevelopmentIn Apache Tomcat versions from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98 a critical severity vulnerability CVE-2025-24813 was detected. This vulnerability allows unauthenticated attackers to upload malicious files and execute arbitrary code on the server due to improper handling of file paths containing internal dots (.), which leads to path equivalence issues under specific non-default configurations. To address this issue, users should upgrade Apache Tomcat to versions 11.0.3, 10.1.35, 9.0.99 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24813.
Read more Application DevelopmentIn Apache Superset versions through 4.1.1 a medium severity vulnerability CVE-2025-27696 was detected. This vulnerability allows authenticated users with read permissions to take ownership of dashboards, charts, or datasets. To address this issue, users should upgrade Apache Superset to versions 4.1.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27696.
Read more Data AnalyticsIn Apache ActiveMQ versions from 6.0.0 before 6.1.6, 5.18.0 before 5.18.7, 5.17.0 before 5.17.7 and before 5.16.8 a medium severity vulnerability CVE-2025-27533 was detected. This vulnerability allows attackers to trigger excessive memory allocation during unmarshalling of OpenWire commands, leading to a denial of service (DoS). To address this issue, users should upgrade Apache ActiveMQ to versions 6.1.6+, 5.19.0+, 5.18.7+, 5.17.7 or 5.16.8. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27533.
Read more Developer ToolsIn Apache Tomcat versions from 9.0.76 through 9.0.102, 10.1.10 through 10.1.39 and 11.0.0-M2 through 11.0.5 a high severity vulnerability CVE-2025-31650 was detected. This vulnerability allows improper input validation of HTTP priority headers, leading to memory leaks and potential denial of service (DoS) due to an OutOfMemoryException. To address this issue, users should upgrade Apache Tomcat to versions 9.0.104, 10.1.40 or 11.0.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-31650.
Read more Application DevelopmentIn Newsletters plugin for WordPress versions up to and including 4.9.9.8 a medium severity vulnerability CVE-2025-3107 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to perform time-based SQL Injection via the ‘orderby’ parameter, enabling them to extract sensitive information from the database. To address this issue, users should upgrade Newsletters plugin to versions 4.9.9.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3107.
Read more CMSIn Firelight Lightbox plugin for WordPress versions prior to 2.3.15 a medium severity vulnerability CVE-2025-3597 was detected. This vulnerability lets authenticated users with post-writing access run harmful JavaScript when the jQuery Metadata feature is enabled, even in the free version of the plugin. To address this issue, users should upgrade Firelight Lightbox plugin to versions 2.3.15 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3597.
Read more CMSIn Frontend Dashboard plugin for WordPress versions 1.0 to 2.2.7 a high severity vulnerability CVE-2025-4474 was detected. This vulnerability allows authenticated attackers with Subscriber-level access and above to escalate privileges by overwriting the plugin’s ‘register’ role setting, making new user registrations default to the administrator role. To address this issue, users should upgrade Frontend Dashboard plugin to versions 2.2.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-4474.
Read more CMS