Comprehensive summary of vulnerabilities and security news from the past 14 days.
In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible...
Jenkins versions 2.56 and earlier as well as 2.46.1 LTS and earlier are vulnerable to an unauthenticated remote code execution. An unauthenticated remote code execution vulnerability allowed attackers...
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints....
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or com...
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allo...
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3 amd BIG-IQ 7.1.0.x before 7.1.0.3 and 7.0.0.x before 7.0.0.2...
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication....
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to ...
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.12.3 (the fixed version for 6.12.x), from version 6.13.0 befo...
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable v...
| CVE ID | CVSS | EPSS | Description |
|---|---|---|---|
| CVE-2025-66131 | 9.1 | 0.0% | Missing Authorization vulnerability in yaadsarig Yaad Sarig Payment Gateway For WC yaad-sarig-paymen... |
| CVE-2025-65318 | 9.1 | 0.1% | When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to... |
| CVE-2025-65319 | 9.1 | 0.1% | When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents t... |
| CVE-2023-53894 | 9.8 | 0.1% | phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by explo... |
| CVE-2023-53895 | 9.8 | 0.1% | PimpMyLog 1.7.14 contains an improper access control vulnerability that allows remote attackers to c... |
Last data sync: 2025-12-29T20:32:23.464550
Generated by InfoSecCenter Security Intelligence Hub