In OpenShift version 4 a medium severity vulnerability CVE-2025-0750 was detected in CRI-O. This vulnerability allows an attacker with permissions to create and delete Pods to unmount arbitrary host paths due to a path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs). Currently, there is no fix version for this issue. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-0750.
Read more Developer ToolsIn Prestashop versions 8.1.7 a medium severity vulnerability CVE-2025-1230 was detected. This vulnerability allows attackers to exploit a Stored Cross-Site Scripting (XSS) flaw due to the lack of proper validation of user input through ‘/
In Brizy – Page Builder plugin for WordPress versions 2.6.8 and prior a medium severity vulnerability CVE-2024-10322 was detected. This vulnerability allows authenticated attackers with Author-level access and above to exploit insufficient input sanitization and output escaping via REST API SVG file uploads, potentially resulting in stored Cross-Site Scripting (XSS) attacks that inject arbitrary web scripts, which execute whenever a user accesses the SVG file. To address this issue, users should upgrade Brizy – Page Builder plugin to version 2.6.9 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10322.
Read more Newsflash Business and Enterprise SolutionsIn Welcart e-Commerce plugin for WordPress versions 2.11.9 and prior a high severity vulnerability CVE-2025-0511 was detected. This vulnerability allows attackers to exploit insufficient input sanitization and output escaping via the ‘name’ parameter, enabling unauthenticated attackers to inject arbitrary web scripts in pages, which will execute whenever a user accesses an injected page. To address this issue, users should upgrade Welcart e-Commerce plugin to version 2.11.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0511.
Read more Newsflash Business and Enterprise SolutionsIn GitLab all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5, and 16.8 prior to 16.8.2 a medium severity vulnerability CVE-2023-6386 was detected. This vulnerability allows attackers to spike the GitLab instance’s resource usage, leading to service degradation and potential downtime. To fix this issue, users should upgrade GitLab CE/EE to versions 16.6.7, 16.7.5, or 16.8.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2023-6386.
Read more Developer ToolsIn WP Foodbakery plugin for WordPress versions 3.3 and prior a critical severity vulnerability CVE-2025-0180 was detected. This vulnerability allows attackers to gain administrator access to a WordPress site by exploiting a flaw in the WP Foodbakery plugin, enabling them to register as an admin without authentication. This vulnerability remains unresolved at this time. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2025-0180.
Read more CMS Newsflash Business and Enterprise SolutionsIn Wazuh versions starting from 4.4.0 and prior to 4.9.1 a high severity vulnerability CVE-2025-24016 was detected. This vulnerability allows attackers to execute malicious code on Wazuh servers by exploiting a flaw in how data is processed, potentially compromising the server. To fix this issue users should upgrade Wazuh to version 4.9.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2025-24016.
Read more SecurityIn GitLab CE/EE all versions starting from 7.14.1 prior to 17.3.7, 17.4 prior to 17.4.4, and 17.5 prior to 17.5.2 a medium severity vulnerability CVE-2025-1072 was detected. This vulnerability allows attackers to cause a denial of service by importing maliciously crafted content using the Fogbugz importer. To fix this issue, users should upgrade GitLab CE/EE to versions 17.3.7, 17.4.4, or 17.5.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2025-1072.
Read more Developer ToolsIn the gitlab-web-ide-vscode-fork component distributed over CDN versions prior to 1.89.1-1.0.0-dev-20241118094343, used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and temporarily affecting versions 17.4, 17.5, and 17.6 a high severity vulnerability CVE-2024-10383 was detected. This vulnerability allows attackers to perform an XSS attack when loading .ipynb files in the web IDE. To fix this issue, users should upgrade to the latest version of gitlab-web-ide-vscode-fork and GitLab. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-10383.
Read more Developer Tools