Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1.3 CVE-2025-53904

The Scratch Channel Has Potential Reflected Cross-Site Scripting (XSS) Vulnerability_CVE-2025-53904

The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/admin.js` contains code that could make ...

The-Scratch-Channel the-scratch-channel.github.io <= b66a1cae45e05ad8971aecd96c3322520f8a5725 CVE
LOW 3.4 CVE-2025-7339

on-headers vulnerable to http response header manipulation_CVE-2025-7339

on-headers is a node.js middleware for listening to when a response writes headers. A bug in on-headers versions `

jshttp on-headers CVE
LOW 2.2 CVE-2025-6227

Invite token is used as part of the secure communication_CVE-2025-6227

Mattermost versions 10.5.x

Mattermost Mattermost 10.5.0 CVE
LOW 3.5 CVE-2025-53901

Wasmtime has host panic with `fd_renumber` WASIp1 function_CVE-2025-53901

Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation of the WASIp1 set of import...

bytecodealliance wasmtime < 24.0.4 CVE
LOW 2.3 CVE-2025-7882

Mercusys MW301R Login excessive authentication_CVE-2025-7882

A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown proce...

Mercusys MW301R 1.0.2 Build 190726 Rel.59423n CVE
LOW 3.1 CVE-2025-8713

PostgreSQL optimizer statistics can expose sampled data within a view, partition, or child table_CVE-2025-8713

PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately, statistics allow a user t...

n/a PostgreSQL 17 CVE
LOW 3.7 CVE-2025-54352

CVE-2025-54352_CVE-2025-54352

WordPress 3.5 through 6.8.2 allows remote attackers to guess titles of private and draft posts via pingback.ping XML-RPC requests. NOTE: the Suppli...

WordPress WordPress 3.5 CVE
LOW 3.9 CVE-2025-44657

CVE-2025-44657_CVE-2025-44657

In Linksys EA6350 V2.1.2, the chroot_local_user option is enabled in the dynamically generated vsftpd configuration file. This could lead to unauth...

n/a n/a n/a CVE
LOW 2.4 CVE-2025-52580

CVE-2025-52580_CVE-2025-52580

Insertion of sensitive information into log file issue exists in "region PAY" App for Android prior to 1.5.28. If exploited, sensitive user informa...

Gift Pad Co.,Ltd. "region PAY" App for Android prior to 1.5.28 CVE
LOW 3.6 CVE-2025-4878

Libssh: use of uninitialized variable in privatekey_from_file()_CVE-2025-4878

A vulnerability was found in libssh, where an uninitialized variable exists under certain conditions in the privatekey_from_file() function. This f...

N/A N/A CVE