Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.2 CVE-2025-59453

CVE-2025-59453_CVE-2025-59453

Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL ...

clickstudios Passwordstate CVE
LOW 3.2 CVE-2025-59436

CVE-2025-59436_CVE-2025-59436

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globall...

fedorindutny ip CVE
LOW 3.2 CVE-2025-59437

CVE-2025-59437_CVE-2025-59437

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly categorized as globally routable ...

fedorindutny ip CVE
LOW 2.1 CVE-2025-43798

CVE-2025-43798_CVE-2025-43798

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TO...

Liferay DXP 7.3.10 CVE
LOW 3.1 CVE-2025-59399

CVE-2025-59399_CVE-2025-59399

libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.

EVerest libocpp CVE
LOW 3.1 CVE-2025-59398

CVE-2025-59398_CVE-2025-59398

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a Ci...

EVerest libocpp CVE
LOW 2.3 CVE-2025-43792

CVE-2025-43792_CVE-2025-43792

Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7...

Liferay Portal 7.4.0 CVE
LOW 3.7 CVE-2025-59376

CVE-2025-59376_CVE-2025-59376

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g...

feiskyer mcp-kubernetes-server CVE
LOW 3.7 CVE-2025-59377

CVE-2025-59377_CVE-2025-59377

feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOT...

feiskyer mcp-kubernetes-server CVE
LOW 3.1 CVE-2025-9084

Open redirect in OAuth login_CVE-2025-9084

Mattermost versions 10.5.x

Mattermost Mattermost 10.5.0 CVE