A vulnerability marked as problematic has been reported in Liferay Portal and DXP. Affected is an unknown function of the component Publications. This manipulation of the argument _com_liferay_change_tracking_web_portlet_PublicationsPortlet_ctCollectionId causes authorization bypass.
The identification of this vulnerability is CVE-2025-62244. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Liferay Portal and DXP. Affected by this issue is some unknown functionality of the component Publications. Performing manipulation of the argument _com_liferay_change_tracking_web_portlet_PublicationsPortlet_value results in incorrect authorization.
This vulnerability is identified as CVE-2025-62243. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in WatchGuard Fireware OS up to 12.11.4/2025.1.2. It has been declared as critical. The impacted element is an unknown function of the component Mobile User VPN. Executing manipulation can lead to release of reference.
This vulnerability is handled as CVE-2025-11838. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in JetBrains TeamCity up to 2025.10. Affected by this vulnerability is an unknown functionality. The manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2025-67740. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability classified as problematic was found in IBM QRadar SIEM up to 7.5.0 UP13 IF02. This affects an unknown function. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-36138. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability, which was classified as problematic, has been found in IBM QRadar SIEM up to 7.5.0 UP13 IF02. This impacts an unknown function of the component Web UI. This manipulation causes cross site scripting.
This vulnerability appears as CVE-2025-36170. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.