Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1 CVE-2025-12888

Constant Time Issue with Xtensa-based ESP32 and X22519_CVE-2025-12888

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU archit...

wolfSSL wolfSSL 5.8.2 CVE
LOW 2.1 CVE-2025-11931

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt_CVE-2025-11931

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCh...

wolfSSL wolfSSL 5.8.4 CVE
LOW 2.3 CVE-2025-11932

Timing Side-Channel in PSK Binder Verification_CVE-2025-11932

The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder

wolfSSL wolfSSL 5.8.4 CVE
LOW 2.3 CVE-2025-12889

TLS 1.2 Client Can Downgrade Digest Used_CVE-2025-12889

With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.

wolfSSL wolfSSL 5.8.4 CVE
LOW 1.9 CVE-2025-13425

Denial of Service in OSV-SCALIBR_CVE-2025-13425

A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for ...

Google OSV-SCALIBR < 0.3.4 CVE
LOW 3.3 CVE-2025-64524

CUPS rastertopclx Filter Vulnerable to Heap Buffer Overflow Leading to Potential Arbitrary Code Execution_CVE-2025-64524

cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos...

OpenPrinting cups-filters <= 2.0.1 CVE
LOW 3.5 CVE-2025-35029

Medical Informatics Engineering Enterprise Health stored cross site scripting via Demographic Information page_CVE-2025-35029

Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbi...

Medical Informatics Engineering Enterprise Health RC202503 CVE
LOW 3.5 CVE-2025-64757

Astro Development Server is Vulnerable to Arbitrary Local File Read_CVE-2025-64757

Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's development server that allows arbi...

withastro astro < 5.14.3 CVE
LOW 2.3 CVE-2025-11884

Cross-site Scripting vulnerability discovered in OpenText™ Universal Discovery and CMDB_CVE-2025-11884

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uCMDB allows Stored XSS. The ...

OpenText™ uCMDB 24.4 CVE
LOW 3.5 CVE-2025-63292

CVE-2025-63292_CVE-2025-63292

Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmwar...

n/a n/a n/a CVE