CVE-2025-54549

Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

CVE-2025-54548

On affected platforms, restricted users could view sensitive portions of the config database via a debug API (e.g., user password hashes)

CVE-2025-54547

On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired

CVE-2025-11947

A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File Handler. Executing manipulation can lead to heap-based buffer overflow. It is possible to launch the attack on the local...

CVE-2025-11946

A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp of the component Add Contact Page. Performing manipulation of the argument First Name/Last...