Comprehensive summary of vulnerabilities and security news from the past 30 days.
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible...
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers...
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints....
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or com...
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allo...
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2...
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication....
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to ...
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 befo...
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v...
| CVE ID | CVSS | EPSS | Description |
|---|---|---|---|
| CVE-2025-13615 | 9.8 | 0.1% | The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions... |
| CVE-2025-35028 | 9.1 | 0.0% | By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the ... |
| CVE-2025-12106 | 9.1 | 0.1% | Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger... |
| CVE-2025-63525 | 9.6 | 0.0% | An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perf... |
| CVE-2025-63531 | 10.0 | 0.1% | A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogi... |
Last data sync: 2025-12-29T03:58:07.831627
Generated by InfoSecCenter Security Intelligence Hub