Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2025-64181

OpenEXR Makes Use of Uninitialized Memory_CVE-2025-64181

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In...

AcademySoftwareFoundation openexr >= 3.3.0, < 3.3.6 CVE
LOW 3.5 CVE-2025-62780

changedetection.io vulnerable to stored XSS in Watch update via API_CVE-2025-62780

changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in changedetection.io Watch updat...

dgtlmoon changedetection.io < 0.50.34 CVE
LOW 2.7 CVE-2025-64529

SpiceDB’s WriteRelationships fails silently if payload is too big_CVE-2025-64529

SpiceDB is an open source database system for creating and managing security-critical application permissions. In versions prior to 1.45.2, users w...

authzed spicedb < 1.45.2 CVE
LOW 2.7 CVE-2025-42883

Insecure File Operations vulnerability in SAP NetWeaver Application Server for ABAP (Migration Workbench)_CVE-2025-42883

Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an attacker with administrativ...

SAP_SE SAP NetWeaver Application Server for ABAP (Migration Workbench) SAP_BASIS 700 CVE
LOW 3.1 CVE-2025-8998

CVE-2025-8998_CVE-2025-8998

It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and impact usability. This flaw ...

Axis Communications AB AXIS OS 6.50.0 CVE
LOW 3.1 CVE-2025-64686

CVE-2025-64686_CVE-2025-64686

In JetBrains YouTrack before 2025.3.104432 missing user principal cleanup led to reuse of incorrect authorization context

JetBrains YouTrack CVE
LOW 2.7 CVE-2025-64682

CVE-2025-64682_CVE-2025-64682

In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit

JetBrains Hub CVE
LOW 2.7 CVE-2025-64681

CVE-2025-64681_CVE-2025-64681

In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations

JetBrains Hub CVE
LOW 2.3 CVE-2025-12918

yungifez Skuul School Management System View Fee Invoice fee-invoices resource injection_CVE-2025-12918

A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an unknown function of the file...

yungifez Skuul School Management System 2.6.0 CVE
LOW 3.1 CVE-2025-11219

CVE-2025-11219_CVE-2025-11219

Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bounds memory access via a cra...

Google Chrome 141.0.7390.54 CVE