In MongoDB Server versions prior to 7.0.28, 8.0.17, 8.2.3, 6.0.27, 5.0.32, 4.4.30, and versions greater than or equal to 4.2.0, 4.0.0, and 3.6.0 a high severity vulnerability CVE-2025-14847 was detected. This vulnerability may allow an unauthenticated client to read uninitialized heap memory due to mismatched length fields in Zlib compressed protocol headers. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14847.
Read more DatabaseIn Jenkins versions 2.56 and earlier, including LTS 2.46.1 and earlier a critical severity vulnerability CVE-2017-1000353 was detected. This vulnerability allows unauthenticated attackers to execute arbitrary code by sending a serialized Java SignedObject to the Jenkins CLI, bypassing existing blacklist-based protections. To address this issue, users should upgrade Jenkins to version 2.57 or LTS 2.46.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-1000353.
Read more Newsflash Developer ToolsIn Discourse versions prior to 3.5.3, 2025.11.1 and 2025.12.0 a medium severity vulnerability CVE-2025-64528 was detected. This vulnerability allows attackers to discover user identities by searching for partial usernames, even when the enable_names setting is disabled, potentially exposing private user information through the UI or API. To address this issue, users should upgrade Discourse to versions 3.5.3, 2025.11.1, 2025.12.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-64528.
Read more CommunicationIn Temporal versions through 1.29.1 a medium severity vulnerability CVE-2025-14987 was detected. This vulnerability allows attackers to perform unauthorized cross-namespace workflow actions due to improper authorization checks when handling workflow task commands, enabling a worker authorized for one namespace to create, signal, or cancel workflows in another namespace. To address this issue, users should upgrade Temporal to versions 1.27.4, 1.28.2 or 1.29.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14987.
Read more Application DevelopmentIn Temporal versions 1.24.0 through 1.29.1 a low severity vulnerability CVE-2025-14986 was detected. This vulnerability allows an attacker authorized in one namespace to bypass namespace-level policy enforcement by exploiting the ExecuteMultiOperation feature, causing validation to occur against an incorrect namespace and enabling operations governed by another namespace’s policies. To address this issue, users should upgrade Temporal to versions 1.27.4, 1.28.2 or 1.29.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14986.
Read more Application DevelopmentIn PHP versions 8.1 before 8.1.34, 8.2 before 8.2.30, 8.3 before 8.3.29, and 8.4 before 8.4.16 a high severity vulnerability CVE-2025-14180 was detected. This vulnerability affects the PDO PostgreSQL driver when PDO::ATTR_EMULATE_PREPARES is enabled and may lead to a null pointer dereference caused by invalid character sequences in prepared statement parameters, resulting in server crashes and reduced availability. To address this issue, users should upgrade to PHP version 8.1.34, 8.2.30, 8.3.29, 8.4.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14180.
Read more Web DevelopmentIn PHP versions 8.1 before 8.1.34, 8.2 before 8.2.30, 8.3 before 8.3.29, 8.4 before 8.4.16, and 8.5 before 8.5.1 a medium severity vulnerability CVE-2025-14178 was detected. This vulnerability affects the array_merge() function and may lead to memory corruption or crashes due to a heap buffer overflow when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE. To address this issue, users should upgrade to PHP version 8.1.34, 8.2.30, 8.3.29, 8.4.16 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-14178.
Read more Web DevelopmentIn the Helpdesk Integration plugin for WordPress versions up to 5.8.10 a high severity vulnerability CVE-2025-9990 was detected. This vulnerability allows unauthenticated attackers to include and execute arbitrary .php files via the portal_type parameter, potentially bypassing access controls, obtaining sensitive data, or executing code. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-9990.
Read more CMSIn Kimai version 1.30.10 a critical severity vulnerability CVE-2023-53957 was detected. This vulnerability allows attackers to exploit improper SameSite cookie handling to steal user session cookies, potentially leading to session hijacking. An attacker can trick a victim into executing a crafted PHP script that captures and writes session cookie data, enabling unauthorized access to the user’s account. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-53957.
Read more Project Management