7.2
CVE-2025-58179 - Astro Cloudflare adapter is vulnerable to Server-Side Request Forgery via /_image endpoint
Astro is a web framework for content-driven websites. Versions 11.0.3 through 12.6.5 are vulnerable to SSRF when using Astro's Cloudflare adapter. When configured with output: 'server' while using the default imageService: 'compile', the generated image optimization endpoint doesn't check the URLs β¦
2.1
CVE-2025-58352 - Weblate has long session expiry times during second factor verification
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
5.1
CVE-2025-55739 - api: Shared OAuth Signing Key Between Different Instances
api is a module for FreePBX@, which is an open source GUI that controls and manages AsteriskΒ© (PBX). In versions lower than 15.0.13, 16.0.2 through 16.0.14, 17.0.1 and 17.0.2, there is an identical OAuth private key used across multiple systems that installed the same FreePBX RPM or DEB package. Anβ¦
9
CVE-2025-55241 - Azure Entra Elevation of Privilege Vulnerability
Azure Entra Elevation of Privilege Vulnerability
7.5
CVE-2025-55238 - Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability
10
CVE-2025-54914 - Azure Networking Elevation of Privilege Vulnerability
Azure Networking Elevation of Privilege Vulnerability
6.5
CVE-2025-55242 - Xbox Certification Bug Copilot Djando Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose information over a network.
9
CVE-2025-55244 - Azure Bot Service Elevation of Privilege Vulnerability
Azure Bot Service Elevation of Privilege Vulnerability
6.1
CVE-2025-55305 - Electron is vulnerable to Code Injection via resource modification
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impactsβ¦
5.1
CVE-2025-55209 - FreePBX UCP is Vulnerable to Stored XSS Through its User Control Panel
contactmanager is a module for FreePBX@, which is an open source GUI that controls and manages AsteriskΒ© (PBX). In versions 15.0.14 and below, 16.0.0 through 16.0.26.4 and 17.0.0 through 17.0.5, a stored cross-site scripting (XSS) vulnerability in FreePBX allows a low-privileged User Control Panelβ¦