In GitLab EE versions 16.2 prior to 17.7.6, 17.8 prior to 17.8.4 and 17.9 prior to 17.9.1 a medium severity vulnerability CVE-2024-10925 was detected. This vulnerability allows attackers to access and view sensitive security configurations in the system. To fix this issue, users should upgrade GitLab EE to versions 17.7.6, 17.8.4 or 17.9.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10925.
Read more Developer ToolsIn GitLab CE/EE versions 16.6 before 17.7.6, 17.8 before 17.8.4 and 17.9 before 17.9.1 a medium severity vulnerability CVE-2024-8186 was detected. This vulnerability allows attackers to inject HTML into the child item search, potentially leading to cross-site scripting (XSS) in certain situations. To address this issue, users should upgrade GitLab CE/EE to versions 17.9.1, 17.8.4 or 17.7.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8186.
Read more Developer ToolsIn the Admin and Site Enhancements (ASE) plugin for WordPress versions before 7.6.10 a medium severity vulnerability CVE-2024-13685 was detected. This vulnerability allows attackers to manipulate client IP addresses via untrusted headers, potentially bypassing the login limit feature. To address this issue, users should upgrade Admin and Site Enhancements (ASE) plugin to version 7.6.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13685.
Read more CMS Newsflash Business and Enterprise SolutionsIn GitLab EE versions 16.6 prior to 16.7.6, 17.8 prior to 17.8.4 and 17.9 prior to 17.9.1 a high severity vulnerability CVE-2025-0555 was detected. This vulnerability allows attackers to bypass security controls and execute arbitrary scripts in a user’s browser under specific conditions. To address this issue, users should upgrade GitLab EE to versions 17.9.1, 17.8.4 or 17.7.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0555.
Read more Developer ToolsIn MinIO versions starting in RELEASE.2024-06-06T09-36-42Z and prior to
RELEASE.2025-02-28T09-55-16Z a medium severity vulnerability CVE-2025-27414 was detected. This vulnerability allows attackers to bypass authentication and gain unauthorized data access by exploiting a bug in evaluating the trust of the SSH key used in an SFTP connection. To address this issue, users should upgrade MinIO to version RELEASE.2025-02-28T09-55-16Z. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-27414.
In Odoo Community version 15.0 and Odoo Enterprise version 15.0 a high severity vulnerability CVE-2024-12368 was detected. This vulnerability allows an internal user to export the OAuth tokens of other users. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12368.
Read more ERPIn WP Posts Carousel plugin for WordPress versions 1.3.7 and prior a medium severity vulnerability CVE-2025-1491 was detected. This vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages, which will execute whenever a user accesses the injected page, due to insufficient input sanitization and output escaping in the ‘auto_play_timeout’ parameter. To address this issue, users should upgrade WP Posts Carousel plugin to versions 1.3.8 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1491.
Read more CMS Newsflash Business and Enterprise SolutionsIn GenerateBlocks plugin for WordPress versions 1.9.1 and prior a medium severity vulnerability CVE-2024-13546 was detected. This vulnerability allows attackers with Contributor-level access and above to extract sensitive information, including the content of private, draft, and scheduled posts and pages, via the ‘get_image_description’ function. To address this issue, users should upgrade GenerateBlocks plugin to versions 2.0.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-13546.
Read more CMS Newsflash Business and Enterprise SolutionsIn Academist Membership plugin for WordPress versions 1.1.6 and prior a critical severity vulnerability CVE-2025-1671 was detected. This vulnerability allows unauthenticated attackers to escalate their privileges and log in as any user, including site administrators, due to improper identity verification in the academist_membership_check_facebook_user() function. To address this issue, users should upgrade Academist Membership plugin to versions 1.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1671.
Read more CMS Newsflash Business and Enterprise Solutions