Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2025-61587

Weblate integration with Anubis can lead to Open Redirect via redir parameter_CVE-2025-61587

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Webl...

WeblateOrg weblate < 5.13.3 CVE
LOW 3.3 CVE-2025-58769

auth0-PHP: Improper File Type Handling in Bulk User Import_CVE-2025-58769

auth0-PHP is an SDK for Auth0 Authentication and Management APIs. In versions 3.3.0 through 8.16.0, the Bulk User Import endpoint in applications b...

auth0 laravel-auth0 >= 3.3.0, < 8.17.0 CVE
LOW 3.5 CVE-2025-58054

Discourse is vulnerable to XSS when quoting chat messages_CVE-2025-58054

Discourse is an open-source community discussion platform. Versions 3.5.0 and below are vulnerable to XSS attacks through parsing and rendering of ...

discourse discourse < 3.5.1 CVE
LOW 3.1 CVE-2025-59682

CVE-2025-59682_CVE-2025-59682

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. The django.utils.archive.extract() function, used by ...

djangoproject Django 4.2 CVE
LOW 3.5 CVE-2025-56675

CVE-2025-56675_CVE-2025-56675

The EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive information su...

EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 CVE
LOW 2.4 CVE-2025-23291

CVE-2025-23291_CVE-2025-23291

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A su...

NVIDIA DLS component of NVIDIA License System All versions prior to v3.5.1 and v3.1.7 CVE
LOW 3.3 CVE-2025-11195

Rapid7 AppSpider Project Name Validation Bypass_CVE-2025-11195

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name di...

Rapid7 AppSpider Pro CVE
LOW 3.5 CVE-2025-55795

CVE-2025-55795_CVE-2025-55795

The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email up...

n/a n/a n/a CVE
LOW 2.1 CVE-2025-59163

vet MCP Server SSE Transport DNS Rebinding Vulnerability_CVE-2025-59163

vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP H...

safedep vet < 1.12.5 CVE
LOW 3.3 CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes session token in debug output_CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to s...

Medical Informatics Engineering Enterprise Health RC202503 CVE