Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.4 CVE-2025-13742

Limited HTML injection in emails_CVE-2025-13742

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it wi...

pretix pretix 1.0.0 CVE
LOW 3.7 CVE-2025-2486

UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu_CVE-2025-2486

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of ...

Ubuntu edk2 2024.05 CVE
LOW 2.7 CVE-2025-20373

Sensitive Information Disclosure in “_internal“ index through Splunk Add-On for Palo Alto Networks_CVE-2025-20373

In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the add...

Splunk Splunk Add-on for Palo Alto Networks 2.0 CVE
LOW 2 CVE-2025-13611

Insertion of Sensitive Information into Log File in GitLab_CVE-2025-13611

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that coul...

GitLab GitLab 13.2 CVE
LOW 3.6 CVE-2025-66040

Spotipy has a XSS vulnerability in OAuth callback server_CVE-2025-66040

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth call...

spotipy-dev spotipy < 2.25.2 CVE
LOW 3.2 CVE-2025-55174

CVE-2025-55174_CVE-2025-55174

In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning followed by the partial co...

KDE Skanpage CVE
LOW 2.3 CVE-2025-33200

CVE-2025-33200_CVE-2025-33200

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of th...

NVIDIA DGX Spark All versions prior to OTA0 CVE
LOW 3.2 CVE-2025-33199

CVE-2025-33199_CVE-2025-33199

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow behavior. A successful explo...

NVIDIA DGX Spark All versions prior to OTA0 CVE
LOW 3.3 CVE-2025-33198

CVE-2025-33198_CVE-2025-33198

NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused. A successful exploit of th...

NVIDIA DGX Spark All versions prior to OTA0 CVE
LOW 3.3 CVE-2025-65961

Contao is vulnerable to cross-site scripting in templates_CVE-2025-65961

Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to inject code into the templat...

contao contao >= 4.0.0, < 4.13.57 CVE