Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1.1 CVE-2025-4617

Prisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma Browser_CVE-2025-4617

An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to ...

Palo Alto Networks Prisma Browser 142.15.6.0 CVE
LOW 3.1 CVE-2025-41436

Unauthorized access to archived channel content via threads interface_CVE-2025-41436

Mattermost versions

Mattermost Mattermost <11.0 CVE
LOW 3.4 CVE-2025-13015

Spoofing issue in Firefox_CVE-2025-13015

Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and Firefox ESR < 115.30.

Mozilla Firefox unspecified CVE
LOW 3.3 CVE-2025-63396

CVE-2025-63396_CVE-2025-63396

An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang du...

n/a n/a n/a CVE
LOW 3.1 CVE-2025-12817

PostgreSQL CREATE STATISTICS does not check for schema CREATE privilege_CVE-2025-12817

Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against other CREATE STATISTICS use...

n/a PostgreSQL 18 CVE
LOW 3.1 CVE-2025-11777

Cross-team channel membership access_CVE-2025-11777

Mattermost versions 10.11.x

Mattermost Mattermost 10.11.0 CVE
LOW 3.3 CVE-2025-46370

CVE-2025-46370_CVE-2025-46370

Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low privileged attacker with loca...

Dell Alienware Command Center 6.x (AWCC) N/A CVE
LOW 2.7 CVE-2025-64745

Astro development server error page vulnerable to reflected Cross-site Scripting_CVE-2025-64745

Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) vulnerability exists in Ast...

withastro astro >= 5.2.0, < 5.15.6 CVE
LOW 3.5 CVE-2025-64744

OpenObserve Vulnerable to HTML Injection in Organization Invitation Emails_CVE-2025-64744

OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming an organization with HTML i...

openobserve openobserve <= 0.16.1 CVE
LOW 2.7 CVE-2025-64754

Jitsi Meet has DOM Redirect on Microsoft OAuth Flow_CVE-2025-64754

Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allows attackers to hijack the ...

jitsi jitsi-meet < 2.0.10532 CVE