Comprehensive summary of vulnerabilities and security news from the past 7 days.
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible...
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers...
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints....
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or com...
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allo...
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2...
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication....
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to ...
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 befo...
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v...
| CVE ID | CVSS | EPSS | Description |
|---|---|---|---|
| CVE-2025-14388 | 9.8 | 0.1% | The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null by... |
| CVE-2025-50526 | 9.8 | 0.4% | Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch... |
| CVE-2025-67108 | 10.0 | 0.0% | eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resultin... |
| CVE-2025-67109 | 10.0 | 0.1% | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers... |
| CVE-2024-57521 | 10.0 | 0.3% | SQL Injection vulnerability in RuoYi v.4.7.9 and before allows a remote attacker to execute arbitrar... |
Last data sync: 2025-12-29T20:32:23.464550
Generated by InfoSecCenter Security Intelligence Hub