In Jenkins versions 2.503 and earlier, LTS 2.492.2 and earlier a medium severity vulnerability CVE-2025-31720 was detected. This vulnerability allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration. To address this issue, users should upgrade Jenkins to versions 2.504 or later, or LTS versions 2.492.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-31720.
Read more Developer ToolsIn PHP versions up to 8.1.31, 8.2.27, 8.3.18 and 8.4.4 a medium severity vulnerability CVE-2025-1219 was detected. This vulnerability allows incorrect parsing of documents or bypassing of validations due to the wrong content-type header being used to determine the charset during HTTP redirects. To address this issue, users should upgrade PHP to versions 8.1.32, 8.2.28, 8.3.19, 8.4.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1219.
Read more Web DevelopmentIn PHP versions up to 8.1.31, 8.2.27, 8.3.18 and 8.4.4 a medium severity vulnerability CVE-2025-1734 was detected. This vulnerability allows invalid headers, specifically those missing a colon (:), to be incorrectly treated as valid headers, potentially leading to unexpected behavior or security vulnerabilities such as header injection attacks. To address this issue, users should upgrade PHP to versions 8.1.32, 8.2.28, 8.3.19, 8.4.5 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-1734.
Read more Web DevelopmentIn Apache Camel versions up to 4.10.2 and 4.8.5 a medium severity vulnerability CVE-2025-30177 was detected. This vulnerability allows attackers to inject Camel-specific headers into incoming requests due to a flaw in the custom header filter strategy, potentially altering the behavior of components such as camel-bean or camel-exec. To address this issue, users should upgrade to Apache Camel versions 4.10.3 or 4.8.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-30177.
Read more Application DevelopmentIn Drupal versions prior to 1.10.0 a low severity vulnerability CVE-2025-31694 was detected. This vulnerability allows attackers to bypass security measures within the Two-factor Authentication (TFA) module through forceful browsing, potentially granting unauthorized access to sensitive user data and administrative functionalities. To address this issue, users should upgrade Drupal TFA module to versions 1.10.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-31694.
Read more CMSIn Rancher versions up to 2.8.13, 2.9.7 and 2.10.3 a high severity vulnerability CVE-2025-23391 was detected. This vulnerability allows Restricted Administrators to change the passwords of Administrators without the necessary permissions, potentially leading to unauthorized access and account takeover. To address this issue, users should upgrade Rancher to versions 2.8.14, 2.9.8, 2.10.4 or 2.11.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-21391.
Read more Developer ToolsIn Drupal versions prior to 1.0.1 a low severity vulnerability CVE-2025-31696 was detected. This vulnerability allows attackers to inject malicious scripts into web pages through improper neutralization of input during web page generation, potentially leading to unauthorized actions, data theft, or session hijacking. To address this issue, users must upgrade to version 1.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-31696.
Read more CMSIn Drupal versions prior to 10.3.13, 10.4.3, 11.0.12 and 11.1.3 a low severity vulnerability CVE-2025-3057 was detected. This vulnerability allows attackers to inject malicious scripts into error messages through improper neutralization of input during web page generation, potentially leading to unauthorized access to user data and session manipulation. To address this issue, users must upgrade to version 10.3.13 or later, 10.4.3 or later, 11.0.12 or later, or 11.1.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-3057.
Read more CMSIn Drupal versions 8.0.0 to 10.3.12, 10.4.0 to 10.4.2, 11.0.0 to 11.0.11 and 11.1.0 to 11.1.2 a high severity vulnerability CVE-2025-31673 was detected. This vulnerability allows attackers to bypass authorization checks and access content they should not have permission to view, potentially leading to unauthorized data exposure. To address this issue, users should upgrade Drupal core to versions 10.3.13, 10.4.3, 11.0.12 or 11.1.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-31673.
Read more CMS