Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2025-13872

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio_CVE-2025-13872

Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an at...

ObjectPlanet Opinio 7.26 rev12562 CVE
LOW 3.5 CVE-2025-13129

Business Logic Error in Seneka Software’s Onaylarım_CVE-2025-13129

Improper Enforcement of Behavioral Workflow vulnerability in Seneka Software Hardware Information Technology Trade Contracting and Industry Ltd. Co...

Seneka Software Hardware Information Technology Trade Contracting and Industry Ltd. Co. Onaylarım 25.09.26.01 CVE
LOW 2.1 CVE-2025-13837

Out-of-memory when loading Plist_CVE-2025-13837

When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file can cause OOM and DoS issues

Python Software Foundation CPython CVE
LOW 3.5 CVE-2025-13758

CVE-2025-13758_CVE-2025-13758

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Devolutions Server CVE
LOW 1 CVE-2025-6666

motogadget mo.lock Ignition Lock NFC hard-coded key_CVE-2025-6666

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of th...

motogadget mo.lock Ignition Lock 20251125 CVE
LOW 3.3 CVE-2025-65681

CVE-2025-65681_CVE-2025-65681

An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive...

n/a n/a n/a CVE
LOW 2.9 CVE-2025-66382

CVE-2025-66382_CVE-2025-66382

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

libexpat project libexpat CVE
LOW 2.8 CVE-2025-66372

CVE-2025-66372_CVE-2025-66372

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

mustangproject Mustang CVE
LOW 2.4 CVE-2025-13742

Limited HTML injection in emails_CVE-2025-13742

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it wi...

pretix pretix 1.0.0 CVE
LOW 3.7 CVE-2025-2486

UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu_CVE-2025-2486

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of ...

Ubuntu edk2 2024.05 CVE