Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.4 CVE-2025-2824

IBM Operational Decision Manager HTTP open redirect_CVE-2025-2824

IBM Operational Decision Manager 8.11.0.1, 8.11.1.0, 8.12.0.1, 9.0.0.1, and 9.5.0 could allow a remote attacker to conduct phishing attacks, using ...

IBM Operational Decision Manager 8.11.0.1 CVE
HIGH 7.3 CVE-2025-54595

Pearcleaner’s unauthenticated access to privileged XPC helper allows root command execution_CVE-2025-54595

Pearcleaner is a free, source-available and fair-code licensed mac app cleaner. The PearcleanerHelper is a privileged helper tool bundled with the ...

alienator88 Pearcleaner >= 4.4.0, < 4.5.2 CVE
HIGH 7.2 CVE-2025-54593

FreshRSS is vulnerable to RCE attacks by authenticated admin_CVE-2025-54593

FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on t...

FreshRSS FreshRSS < 1.26.2 CVE
HIGH 8.1 CVE-2025-54424

1Panel Agent Bypasses Certificate Verification Leading to Arbitrary Command Execution_CVE-2025-54424

1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and bel...

1Panel-dev 1Panel < 2.0.6 CVE
HIGH 7.2 CVE-2025-54136

Cursor’s Modification of MCP Server Definitions Bypasses Manual Re-approvals_CVE-2025-54136

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and persistent code execution by m...

cursor cursor < 1.3 CVE
HIGH 7.3 CVE-2025-54386

Traefik’s Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code Execution_CVE-2025-54386

Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerabilit...

traefik traefik <= 2.11.27, < 2.11.28 CVE
HIGH 7.5 CVE-2025-54796

Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through “Recent Uploads” page_CVE-2025-54796

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this...

9001 copyparty < 1.18.9 CVE
HIGH 8.8 CVE-2025-6076

CVE-2025-6076_CVE-2025-6076

Partner Software's Partner Software application and Partner Web application do not sanitize files uploaded on the "reports" tab, allowing an authen...

Partner Software Partner Web 4.32 CVE
HIGH 8.8 CVE-2025-6754

SEO Metrics <= 1.0.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation_CVE-2025-6754

The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_conne...

seometricsplugin SEO Metrics * CVE
HIGH 7.3 CVE-2025-23277

CVE-2025-23277_CVE-2025-23277

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bound...

NVIDIA GPU Display Drivers R575 CVE