Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-11966

CVE-2025-11966_CVE-2025-11966

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into gene...

Eclipse Foundation Vert.x 4.0.0 CVE
LOW 2.1 CVE-2025-62659

The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors_CVE-2025-62659

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki Coo...

The Wikimedia Foundation MediaWiki CookieConsent extension v2.0.0 CVE
LOW 2 CVE-2025-62247

CVE-2025-62247_CVE-2025-62247

Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, ...

Liferay Portal 7.4.0 CVE
LOW 2.6 CVE-2025-62710

Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl_CVE-2025-62710

Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor...

sakaiproject sakai < 23.5 CVE
LOW 3.1 CVE-2025-62774

CVE-2025-62774_CVE-2025-62774

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

Mercku M6a CVE
LOW 2.4 CVE-2025-62773

CVE-2025-62773_CVE-2025-62773

Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.

Mercku M6a CVE
LOW 3.1 CVE-2025-62772

CVE-2025-62772_CVE-2025-62772

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

Mercku M6a CVE
LOW 2.7 CVE-2025-41721

Sauter: Command Injection_CVE-2025-41721

A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralization of special elements whe...

Sauter modulo 6 devices modu680-AS 0.0.0 CVE
LOW 1.8 CVE-2025-11624

Buffer overwrite when processing file handles with the SFTP server_CVE-2025-11624

Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or ...

wolfSSH wolfSSH 1.3.0 CVE
LOW 2.7 CVE-2025-62480

CVE-2025-62480_CVE-2025-62480

{“lastseen”:””,”description”:””,”published”:”2025-10-21T20:03:18.599Z”,&#82...

Oracle Corporation Oracle ZFS Storage Appliance Kit 8.8 CVE