Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-11281

Frappe LMS Unpublished Course courses access control_CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished...

Frappe LMS 2.35.0 CVE
LOW 2.5 CVE-2025-61677

DataChain: Deserialization of Untrusted Data from Environment Variables_CVE-2025-61677

DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and below allow for deseriaization ...

iterative datachain < 0.34.2 CVE
LOW 2.3 CVE-2025-59829

Claude Code: Permission deny bypass is possible through symlink_CVE-2025-59829

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explici...

anthropics claude-code < 1.0.120 CVE
LOW 3.5 CVE-2025-52658

CVE-2025-52658_CVE-2025-52658

HCL MyXalytics  6.6.  product is affected by Use of Vulnerable/Outdated Versions Vulnerability

HCL HCL MyXalytics 6.6 CVE
LOW 3.8 CVE-2025-10306

Backup Bolt <= 1.4.1 - Authenticated (Admin+) Arbitrary File Download_CVE-2025-10306

The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4...

backupbolt Backup Bolt * CVE
LOW 2.1 CVE-2025-27236

User information disclosure via api_jsonrpc.php on method user.get with param search_CVE-2025-27236

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows...

Zabbix Zabbix 6.0.38 CVE
LOW 1.8 CVE-2025-54087

Server-side request forgery in Secure Access_CVE-2025-54087

CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can...

Absolute Security Secure Access CVE
LOW 2.3 CVE-2025-11239

Job details are visible to all team members on KNIME Business Hub_CVE-2025-11239

Potentially sensitive information in jobs on KNIME Business Hub prior to 1.16.0 were visible to all members of the user's team. Starting with KNIME...

KNIME KNIME Business Hub CVE
LOW 2.1 CVE-2025-61587

Weblate integration with Anubis can lead to Open Redirect via redir parameter_CVE-2025-61587

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Webl...

WeblateOrg weblate < 5.13.3 CVE
LOW 3.3 CVE-2025-58769

auth0-PHP: Improper File Type Handling in Bulk User Import_CVE-2025-58769

auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications b...

auth0 laravel-auth0 >= 3.3.0, < 8.17.0 CVE