Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-15122

JeecgBoot datarule loadDatarule improper authorization_CVE-2025-15122

A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Per...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15123

JeecgBoot datarule improper authorization_CVE-2025-15123

A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15117

Dromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserialization_CVE-2025-15117

A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer...

Dromara Sa-Token 1.0 CVE
LOW 2.3 CVE-2025-15119

JeecgBoot list queryPageList improper authorization_CVE-2025-15119

A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manip...

n/a JeecgBoot 3.0 CVE
LOW 2.9 CVE-2025-68932

FreshRSS has weak cryptographic randomness in remember-me token and nonce generation_CVE-2025-68932

FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand()...

FreshRSS FreshRSS < 1.28.0 CVE
LOW 3.1 CVE-2025-36229

Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera Faspex_CVE-2025-36229

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package id...

IBM Aspera Faspex 5 5.0.0 CVE
LOW 3.8 CVE-2025-36228

Incorrect Execution-Assigned Permissions in IBM Aspera Faspex_CVE-2025-36228

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 may allow inconsistent permissions between the user interface and backend API allowed users to access fe...

IBM Aspera Faspex 5 5.0.0 CVE
LOW 3.1 CVE-2025-68940

CVE-2025-68940_CVE-2025-68940

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

Gitea Gitea CVE
LOW 1 CVE-2025-15083

TOZED ZLT M30s UART on-chip debug and test interface with improper access control_CVE-2025-15083

A vulnerability was determined in TOZED ZLT M30s up to 1.47. The affected element is an unknown function of the component UART Interface. Executing...

TOZED ZLT M30s 1.0 CVE
LOW 2.3 CVE-2025-15084

youlaitech youlai-mall Order Payment OrderController.java orderService.payOrder access control_CVE-2025-15084

A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-o...

youlaitech youlai-mall 1.0.0 CVE