Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.6 CVE-2025-61985

CVE-2025-61985_CVE-2025-61985

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

OpenBSD OpenSSH CVE
LOW 2.1 CVE-2025-61769

Emlog vulnerable to stored XSS in file upload functionality in emlog_CVE-2025-61769

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows auth...

emlog emlog <= 2.5.22 CVE
LOW 3.8 CVE-2025-58578

Unlimited user creation by authorized users_CVE-2025-58578

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no qu...

SICK AG Enterprise Analytics all versions CVE
LOW 2.7 CVE-2025-58589

Information Disclosure Through Stacktrace_CVE-2025-58589

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other int...

SICK AG Baggage Analytics all versions CVE
LOW 2.3 CVE-2025-11281

Frappe LMS Unpublished Course courses access control_CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished...

Frappe LMS 2.35.0 CVE
LOW 2.5 CVE-2025-61677

DataChain: Deserialization of Untrusted Data from Environment Variables_CVE-2025-61677

DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and below allow for deseriaization ...

iterative datachain < 0.34.2 CVE
LOW 2.3 CVE-2025-59829

Claude Code: Permission deny bypass is possible through symlink_CVE-2025-59829

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explici...

anthropics claude-code < 1.0.120 CVE
LOW 3.5 CVE-2025-52658

CVE-2025-52658_CVE-2025-52658

HCL MyXalytics  6.6.  product is affected by Use of Vulnerable/Outdated Versions Vulnerability

HCL HCL MyXalytics 6.6 CVE
LOW 3.8 CVE-2025-10306

Backup Bolt <= 1.4.1 - Authenticated (Admin+) Arbitrary File Download_CVE-2025-10306

The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all versions up to, and including, 1.4...

backupbolt Backup Bolt * CVE
LOW 2.1 CVE-2025-27236

User information disclosure via api_jsonrpc.php on method user.get with param search_CVE-2025-27236

A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have access to view. This allows...

Zabbix Zabbix 6.0.38 CVE