CVE-2025-10539 — Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime updat — CVE Database · The Intelligence Room