Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2025-66558

Nextcloud Twofactor WebAuthn app was updated based on public key_CVE-2025-66558

Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an atta...

nextcloud security-advisories < 1.4.2 CVE
LOW 1.3 CVE-2025-66581

Frappe LMS is Missing Server-Side Authorization in Business Logic_CVE-2025-66581

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.41.0, a flaw in the server-side a...

frappe lms < 2.41.0 CVE
LOW 2.3 CVE-2025-14111

Rarlab RAR App com.rarlab.rar path traversal_CVE-2025-14111

A security vulnerability has been detected in Rarlab RAR App up to 7.11 Build 127 on Android. This affects an unknown part of the component com.rar...

Rarlab RAR App 7.11 Build 127 CVE
LOW 3.7 CVE-2025-66629

HedgeDoc is missing state parameter in OAuth2 flows could lead to CSRF_CVE-2025-66629

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social l...

hedgedoc hedgedoc < 1.10.4 CVE
LOW 2.1 MS:CVE-2025-13837

Out-of-memory when loading Plist_MS:CVE-2025-13837

{“lastseen”:”2025-12-05T19:40:21″,”description”:””,”published”:”2025-12-05T01:03:...

N/A N/A MSCVE
LOW 3.5 MS:CVE-2025-13640

Chromium: CVE-2025-13640 Inappropriate implementation in Passwords_MS:CVE-2025-13640

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 2 CVE-2025-14007

dayrui XunRuiCMS Domain Name Binding admin79f2ec220c7e.php cross site scripting_CVE-2025-14007

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mob...

dayrui XunRuiCMS 4.7.0 CVE
LOW 2.2 CVE-2025-12997

CVE-2025-12997_CVE-2025-12997

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device ...

Medtronic CareLink Network CVE
LOW 1.8 CVE-2025-66479

Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing_CVE-2025-66479

Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level...

anthropic-experimental sandbox-runtime < 0.0.16 CVE
LOW 2.7 CVE-2025-12954

Timetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR_CVE-2025-12954

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating...

Unknown Timetable and Event Schedule by MotoPress CVE