Comprehensive summary of vulnerabilities and security news from the past 14 days.
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible...
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers...
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints....
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or com...
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allo...
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2...
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication....
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to ...
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 befo...
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v...
| CVE ID | CVSS | EPSS | Description |
|---|---|---|---|
| CVE-2025-14156 | 9.8 | 0.1% | The Fox LMS – WordPress LMS Plugin plugin for WordPress is vulnerable to privilege escalation in all... |
| CVE-2025-13888 | 9.1 | 0.1% | A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that... |
| CVE-2025-66844 | 9.1 | 0.0% | In grav <1.7.49.5, a SSRF (Server-Side Request Forgery) vector may be triggered via Twig templates w... |
| CVE-2025-66438 | 9.8 | 0.1% | A Server-Side Template Injection (SSTI) vulnerability exists in the Frappe ERPNext through 15.89.0 P... |
| CVE-2025-66439 | 9.8 | 0.0% | An issue was discovered in Frappe ERPNext through 15.89.0. Function get_outstanding_reference_docume... |
Last data sync: 2025-12-29T03:58:07.831627
Generated by InfoSecCenter Security Intelligence Hub