In GitLab CE/EE versions from 17.2 before 17.6.4, 17.7 before 17.7.3 and 17.8 before 17.8.1 a high severity vulnerability CVE-2025-0314 was detected. This vulnerability allows attackers to perform cross-site scripting (XSS) due to improper rendering of certain file types. To address this issue, users should upgrade GitLab CE/EE to versions 17.6.4, 17.7.3, or 17.8.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0314.
Read more Developer ToolsIn GitLab CE/EE versions from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1 a medium severity vulnerability CVE-2024-11931 was detected. This vulnerability allows attackers with a developer role to exfiltrate protected CI variables under certain conditions via CI lint. To address this issue, users should upgrade GitLab CE/EE to versions 17.6.4, 17.7.3, 17.8.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11931.
Read more Developer ToolsIn Keycloak versions 26.1.0 and prior a medium severity vulnerability CVE-2025-0604 was detected. This vulnerability allows attackers to bypass authentication by exploiting a flaw in Active Directory password resets, enabling users with expired or disabled AD accounts to regain access without proper LDAP validation. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-0604.
Read more SecurityIn Directus versions prior to 11.2.0 a medium severity vulnerability CVE-2025-24353 was detected. This vulnerability allows attackers to exploit the item sharing feature to specify an arbitrary role, potentially escalating privileges and accessing fields that should otherwise remain hidden. To address this issue, users should upgrade Directus to version 11.2.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24353.
Read more CMSIn Node.js versions 17.9.1 and prior a high severity vulnerability CVE-2025-23087 was detected. This vulnerability highlights the risks of using unsupported End-of-Life (EOL) versions, exposing systems to unpatched vulnerabilities, including outdated dependencies like OpenSSL v1. To address this issue, users should upgrade Node.js to version 18 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-23087.
Read more Application DevelopmentIn Umbraco versions 14.0.0 up to 14.3.1 and 15.0.0 up to 15.1.1 a medium severity vulnerability CVE-2025-24011 was detected. This vulnerability allows attackers to determine if an account exists by analyzing response codes and timing from the management API. To address this issue, users should upgrade Umbraco to versions 14.3.2 or 15.1.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-24011.
Read more CMSIn Kibana versions from 8.7.0 up to 8.15.0 a medium severity vulnerability CVE-2024-43710 was detected. This vulnerability allows attackers to exploit the /api/fleet/health_check API to send server-side requests to internal endpoints, with the limitation that only HTTPS endpoints returning JSON data can be accessed. To address this issue, users should upgrade Kibana to versions 8.15.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43710.
Read more Data AnalyticsIn Kibana versions up to 7.17.23 and 8.15.0 a medium severity vulnerability CVE-2024-43708 was detected. This vulnerability allows attackers to crash Kibana by sending a specially crafted payload to multiple inputs in the Kibana UI, exploiting the lack of resource allocation limits or throttling. To address this issue, users should upgrade Kibana to versions 7.17.23 or 8.15.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43708.
Read more Data AnalyticsIn Kibana versions from 8.0.0 up to 8.15.0 a high severity vulnerability CVE-2024-43707 was detected. This vulnerability allows attackers to view Elastic Agent policies without proper access, potentially exposing sensitive information based on the integrations enabled and their versions. To address this issue, users should upgrade Kibana to versions 8.15.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-43707.
Read more Data Analytics