Latest Vulnerabilities In the past week, numerous vulnerabilities affecting a variety of software have come to light, highlighting a broad range of security issues that could put users at risk. WordPress plugins, particularly Tripetto and Contact Manager, have shown weaknesses that allow unauthorized file uploads. In addition, several vulnerabilities in Adobe Experience Manager point to serious cross-site scripting flaws, posing risks to user data. Other notable vulnerabilities include issues with Veeam Updater that could enable man-in-the-middle attacks, and local privilege escalation problems in Parallels Desktop and Omnissa Horizon Client for macOS. These findings emphasize the need for vigilance in keeping software updated.
IBM PowerHA SystemMirror for IBM i IBM-7180036 More details
First published (updated )
IBM WebSphere Automation IBM-7179994 More details
First published (updated )
Tripetto Tripetto WordPress form builder plugin for contact forms, surveys and quizzes – Tripetto <= 8.0.8 - Unauthenticated Sensitive Information Exposure More details
First published (updated )
Cockpit Malicious File Upload More details
First published (updated )
Spatie Browsershot Input Validation More details
First published (updated )
Spatie Browsershot Input Validation More details
First published (updated )
WordPress Contact Manager Contact Manager <= 8.6.4 - Unauthenticated Arbitrary Double File Extension Upload More details
First published (updated )
Veeam Updater A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary c… More details
First published (updated )
NETGEAR XR1000 firmware Code Injection More details
First published (updated )
Ubuntu Linux Kerberos vulnerability More details
First published (updated )
redhat/libsoup Important: libsoup security update More details
First published (updated )
Adobe Experience Manager Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) More details
First published (updated )
Adobe Experience Manager Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) More details
First published (updated )
Adobe Experience Manager Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) More details
First published (updated )
Adobe Experience Manager Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79) More details
First published (updated )
Adobe Experience Manager Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79) More details
First published (updated )
Parallels Desktop for Mac Parallels Desktop Technical Data Reporter Link Following Local Privilege Escalation Vulnerability More details
First published (updated )
Omnissa Horizon Client Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a … More details
First published (updated )
CVE-2023-39943 Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds Write More details
First published (updated )
Ashlar-Vellum Cobalt Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Heap-based Buffer Overflow More details
First published (updated )
Omnissa Horizon Client Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a … More details
First published (updated )
Checkmk NagVis Checkmk NagVis Reflected Cross-site Scripting More details
First published (updated )
Checkmk NagVis Checkmk NagVis Remote Code Execution More details
First published (updated )
swift/github.com/sparkle-project/Sparkle A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing sign… More details
First published (updated )
OpenText Content Management A remote code vulnerability has been discovered in OpenText™ Content Management. More details
First published (updated )
go/github.com/edgelesssys/marblerun ### Impact
During recovery, a Coordinator only verifies that a given recovery key decrypts the seal… More details
First published (updated )
Discourse Discourse Cross-site Scripting (XSS) via topic titles when CSP disabled in Discourse More details
First published (updated )
Discourse Discourse Partial denial of service via inline oneboxes in Discourse More details
First published (updated )
Discourse Discourse Discourse is an open source platform for community discussion. In affected versions an attacker can … More details
First published (updated )
Discourse Discourse Potential bypass of chat permissions in Discourse More details
First published (updated )
Discourse Discourse Anonymous cache poisoning via XHR requests in Discourse More details
First published (updated )
Discourse Discourse Users can see other user's tagged PMs in Discourse More details
First published (updated )
Discourse Discourse HTMLi(XSS without CSP) via Onebox urls in Discourse More details
First published (updated )
Discourse Discourse Client Side Path Traversal using activate account route in Discourse More details
First published (updated )
Discourse Discourse Stored DOM-based XSS (without CSP) via video placeholders in Discourse More details
First published (updated )
Sparkle Signing Checks Bypass More details
First published (updated )
Western Telematic Inc Network Power Switch (NPS Series) Western Telematic Inc NPS Series, DSM Series, CPM Series External Control of File Name or Path More details
First published (updated )
AutomationDirect C-more EA9 HMI AutomationDirect C-more EA9 HMI Classic Buffer Overflow More details
First published (updated )
reNgine Business Logic And Unrestricted Project Deletion Lead To Take Over the System in reNgine More details
First published (updated )
reNgine Stored XSS on Admin Panel When Deleting a User in reNgine More details
First published (updated )
reNgine HTML Injection in reNgine More details
First published (updated )
rust/cosmwasm-vm # CWA-2025-002
**Severity**
Medium (Moderate + Likely)[^1]
**Affected versions:**
- wasmvm >= 2.… More details
First published (updated )
go/github.com/CosmWasm/wasmvm/v2 Null Pointer Dereference More details
First published (updated )
DumpDrop OS Command Injection endpoint '/upload/init' parameter 'filename' (RCE) in DumpDrop More details
First published (updated )
WordPress PDF Invoices & Packing Slips for WooCommerce Unrestricted Access to PDF Documents via URL Manipulation in woocommerce-pdf-invoices-packing-slips More details
First published (updated )
Aruba ClearPass Policy Manager Authenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management Interface More details
First published (updated )
Aruba ClearPass Policy Manager Sensitive Data Exposure Vulnerability in HPE Aruba Networking ClearPass Policy Manager (CPPM) More details
First published (updated )
Aruba ClearPass Policy Manager Sensitive Information Disclosure in HPE Aruba Networking ClearPass Policy Manager More details
First published (updated )
Hewlett Packard ClearPass Policy Manager Authenticated Broken Access Control Vulnerability in ClearPass Policy Manager Web-Based Management Interface More details
First published (updated )
BigAnt Server BigAntSoft BigAnt Server Account Registration Bypass to File Upload RCE More details
First published (updated )
Contact SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd. ABN: 70 645 966 203, ACN: 645 966 203