Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.3 CVE-2025-8757

TRENDnet TV-IP110WN Embedded Boa Web Server boa.conf least privilege violation_CVE-2025-8757

A vulnerability was found in TRENDnet TV-IP110WN 1.2.2 and classified as problematic. Affected by this issue is some unknown functionality of the f...

TRENDnet TV-IP110WN 1.2.2 CVE
HIGH 7.1 CVE-2025-55009

AuthKit: Sensitive auth data rendered in HTML_CVE-2025-55009

The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix. In versions ...

workos authkit-remix < 0.15.0 CVE
HIGH 7.1 CVE-2025-55008

AuthKit React Router: Sensitive auth data rendered in HTML_CVE-2025-55008

The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router. In ver...

workos authkit-react-router < 0.7.0 CVE
HIGH 7.8 CVE-2025-50675

CVE-2025-50675_CVE-2025-50675

GPMAW 14, a bioinformatics software, has a critical vulnerability related to insecure file permissions in its installation directory. The directory...

n/a n/a n/a CVE
HIGH 8.7 CVE-2025-54888

@fedify/fedify: Improper Authentication and Incorrect Authorization_CVE-2025-54888

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. In versions below 1.3.20, 1.4.0-dev.585 through 1.4.12, 1...

fedify-dev fedify < 1.3.20 CVE
HIGH 7.2 CVE-2025-54996

OpenBao Root Namespace Operator May Elevate Token Privileges_CVE-2025-54996

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In version...

openbao openbao < 2.3.2 CVE
HIGH 8.1 CVE-2025-47219

CVE-2025-47219_CVE-2025-47219

In GStreamer through 1.26.1, the isomp4 plugin's qtdemux_parse_trak function may read past the end of a heap buffer while parsing an MP4 file, poss...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-46659

CVE-2025-46659_CVE-2025-46659

An issue was discovered in ExonautWeb in 4C Strategies Exonaut 21.6. Information disclosure can occur via an external HTTPS request.

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-47908

Denial of service via malicious preflight requests in github.com/rs/cors_CVE-2025-47908

Middleware causes a prohibitive amount of heap allocations when processing malicious preflight requests that include a Access-Control-Request-Heade...

github.com/rs/cors github.com/rs/cors 1.9.0 CVE
HIGH 8.6 CVE-2025-51055

CVE-2025-51055_CVE-2025-51055

Insecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contains cl...

n/a n/a n/a CVE