| 271810 | Mattermost Server 10.5.x < 10.5.11 / 10.10.x < 10.10.3 / 10.11.x 10.11.2 / 10.12.0 Multiple Vulnerabilities (MMSA-2025-00507, MMSA-2025-00508) | high |
| 271809 | Mattermost Server 10.5.x < 10.5.11 / 10.10.x < 10.10.3 / 10.11.x 10.11.3 / 10.12.0 Missing Authorization (MMSA-2025-00525) | medium |
| 271500 | GitLab 17.10 < 18.3.5 / 18.4 < 18.4.3 / 18.5 < 18.5.1 (CVE-2025-10497) | high |
| 271499 | GitLab 11.7 < 18.3.5 / 18.4 < 18.4.3 / 18.5 < 18.5.1 (CVE-2025-11974) | medium |
| 271498 | GitLab 10.6 < 18.3.5 / 18.4 < 18.4.3 / 18.5 < 18.5.1 (CVE-2025-11971) | medium |
| 271497 | GitLab 11.0 < 18.3.5 / 18.4 < 18.4.3 / 18.5 < 18.5.1 (CVE-2025-11447) | high |
| 271496 | GitLab 18.4 < 18.4.3 / 18.5 < 18.5.1 (CVE-2025-6601) | low |
| 271495 | GitLab 17.6.0 < 18.3.5 / 18.4 < 18.4.3 / 18.5 < 18.5.1 (CVE-2025-11989) | low |
| 271368 | Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability (CVE-2014-3931) | critical |
| 271244 | Oracle Primavera Unifier (October 2025 CPU) | medium |
| 271243 | Oracle Primavera P6 Enterprise Project Portfolio Management (October 2025 CPU) | high |
| 271242 | Oracle Primavera Gateway (October 2025 CPU) | high |
| 271200 | Mattermost Server 10.5.x < 10.5.11 / 10.11.x < 10.11.3 / 10.12.0 Multiple Vulnerabilities (MMSA-2025-00497, MMSA-2025-00496, MMSA-2025-00516) | medium |
| 270349 | Adobe Connect <= 12.9 Multiple Vulnerabilities (APSB25-70) | critical |
| 269974 | Kibana 7.0.x <= 7.17.29 / 8.0.x <= 8.18.7 / 8.19.x <= 8.19.4 / 9.0.x <= 9.0.7 / 9.1.x <= 9.1.4 Multiple XSS (ESA-2025-17, ESA-2025-20) | high |
| 269973 | Kibana 7.0.x <= 7.17.29 / 8.0.x <= 8.18.7 / 8.19.x <= 8.19.3 / 9.0.x <= 9.0.6 / 9.1.x <= 9.1.3 XSS (ESA-2025-16) | high |
| 269804 | Zimbra Collaboration Server 9.x < 9.0.0 Patch 39, 10.0.x < 10.0.13, 10.1.x < 10.1.5 XSS | medium |
| 269803 | GitLab 13.12 < 18.2.8 / 18.3 < 18.3.4 / 18.4 < 18.4.2 (CVE-2025-10004) | high |
| 269802 | GitLab 18.3 < 18.3.4 / 18.4 < 18.4.2 (CVE-2025-11340) | high |
| 269801 | GitLab 5.2 < 18.2.8 / 18.3 < 18.3.4 / 18.4 < 18.4.2 (CVE-2025-2934) | medium |
| 266443 | Splunk Enterprise 9.2.0 < 9.2.8, 9.3.0 < 9.3.6, 9.4.0 < 9.4.4 (SVD-2025-1001) | medium |
| 266411 | Splunk Enterprise 9.2.0 < 9.2.8, 9.3.0 < 9.3.6, 9.4.0 < 9.4.4 (SVD-2025-1004) | medium |
| 266410 | Splunk Enterprise 9.2.0 < 9.2.8, 9.3.0 < 9.3.6, 9.4.0 < 9.4.4 (SVD-2025-1002) | medium |
| 266409 | Splunk Enterprise 9.2.0 < 9.2.8, 9.3.0 < 9.3.6, 9.4.0 < 9.4.4 (SVD-2025-1003) | medium |
| 266359 | Splunk Enterprise 9.2.0 < 9.2.8, 9.3.0 < 9.3.6, 9.4.0 < 9.4.4, 10.0.0 < 10.0.1 (SVD-2025-1005) | medium |
| 266358 | Splunk Enterprise 9.2.0 < 9.2.8, 9.3.0 < 9.3.6, 9.4.0 < 9.4.4, 10.0.0 < 10.0.1 (SVD-2025-1006) | high |
| 266292 | Joomla 4.0.x < 4.4.14 / 5.0.x < 5.3.4 Joomla 5.3.4 Security & Bugfix Release (5936-joomla-5-3-4-security-bugfix-release) | high |
| 266222 | Mattermost Server 10.5.x < 10.5.10 / 10.11.0 URL Redirection (MMSA-2025-00511) | medium |
| 266221 | Mattermost Server 9.11.x < 9.11.18 / 10.5.x < 10.5.9 / 10.11.0 Authorization Bypass (MMSA-2025-00502) | medium |
| 266220 | Mattermost Server 10.5.x < 10.5.10 / 10.9.x < 10.9.5 / 10.10.x < 10.10.2 / 10.11.0 URL Redirection (MMSA-2025-00509) | high |
| 266219 | Mattermost Server 10.10.x < 10.10.2 / 10.11.0 Missing Authorization (MMSA-2025-00513) | medium |
| 266069 | Apache Solr 6.6.x < 9.8.0 Relative Path Traversal | medium |
| 266024 | GitLab 11.10 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-8014) | high |
| 265988 | GitLab 17.2 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-11042) | medium |
| 265987 | GitLab 14.10 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-9642) | high |
| 265982 | GitLab 18.1 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-10867) | low |
| 265981 | GitLab 16.6 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-7691) | medium |
| 265961 | GitLab 17.4 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-10868) | low |
| 265960 | GitLab 17.10 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-5069) | low |
| 265959 | GitLab 16.6 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-10871) | low |
| 265958 | GitLab 14.10 < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-9958) | high |
| 265957 | GitLab < 18.2.7 / 18.3 < 18.3.3 / 18.4 < 18.4.1 (CVE-2025-10858) | high |
| 265948 | Dell Data Domain OS Command Injection (DSA-2025-159) | high |
| 265947 | Dell Data Domain OS Auth Bypass (DSA-2025-159) | critical |
| 265946 | Fortra GoAnywhere Managed File Transfer (MFT) < 7.8.1 Broken Access Control (fi-2025-009) | medium |
| 265889 | Apache Solr < 9.8.0 ConfigSet Privilege Escalation via <lib> Injection (CVE-2025-24814) | medium |
| 265789 | Dotnetnuke < 10.1.0 Stored XSS Using Backend Admin Credentials (CVE-2025-59546) | low |
| 265757 | Dotnetnuke < 10.1.0 Stored Cross-Site Scripting (XSS) in Prompt module (CVE-2025-59545) | critical |
| 265756 | Dotnetnuke < 10.1.0 Reflected Cross-Site Scripting (XSS) using url to profile (CVE-2025-59821) | medium |
| 265752 | Dotnetnuke < 10.1.0 Loading unused themes on annonymous clients through query parameters (CVE-2025-59535) | medium |