Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2025-55212

ImageMagick affected by divide-by-zero in ThumbnailImage via montage -geometry “:” leads to crash_CVE-2025-55212

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a g...

ImageMagick ImageMagick < 7.1.2-2 CVE
LOW 2 CVE-2025-9474

Mihomo Party Socket sysproxy.ts enableSysProxy temp file_CVE-2025-9474

A vulnerability was detected in Mihomo Party up to 1.8.1 on macOS. Affected is the function enableSysProxy of the file src/main/sys/sysproxy.ts of ...

Mihomo Party 1.8.0 CVE
LOW 3.8 CVE-2025-3456

On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting logs. Knowledge of both the encryption key and protocol specific encrypted secrets from the device running-c_CVE-2025-3456

On affected platforms running Arista EOS, the global common encryption key configuration may be logged in clear text, in local or remote accounting...

Arista Networks EOS 4.34.0F CVE
LOW 3.5 CVE-2025-55455

CVE-2025-55455_CVE-2025-55455

DooTask v1.0.51 was dicovered to contain an authenticated arbitrary download vulnerability via the component /msg/sendtext.

n/a n/a n/a CVE
LOW 2 CVE-2025-9383

FNKvision Y215 CCTV Camera passwd crypt weak hash_CVE-2025-9383

A security vulnerability has been detected in FNKvision Y215 CCTV Camera 10.194.120.40. This issue affects the function crypt of the file /etc/pass...

FNKvision Y215 CCTV Camera 10.194.120.40 CVE
LOW 1 CVE-2025-9381

FNKvision Y215 CCTV Camera wpa_supplicant.conf information disclosure_CVE-2025-9381

A security flaw has been discovered in FNKvision Y215 CCTV Camera 10.194.120.40. This affects an unknown part of the file /tmp/wpa_supplicant.conf....

FNKvision Y215 CCTV Camera 10.194.120.40 CVE
LOW 2.1 CVE-2025-54812

Apache Log4cxx: Improper HTML escaping in HTMLLayout_CVE-2025-54812

Improper Output Neutralization for Logs vulnerability in Apache Log4cxx. When using HTMLLayout, logger names are not properly escaped when writin...

Apache Software Foundation Apache Log4cxx CVE
LOW 2.5 CVE-2025-55745

UnoPim Quick Export feature is vulnerable to CSV injection_CVE-2025-55745

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV...

unopim unopim < 0.3.1 CVE
LOW 2.1 CVE-2025-43753

CVE-2025-43753_CVE-2025-43753

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.32 through 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7,...

Liferay Portal 7.4.3.32 CVE
LOW 3.5 CVE-2025-55523

CVE-2025-55523_CVE-2025-55523

An issue in the component /api/download_work_dir_file.py of Agent-Zero v0.8.* allows attackers to execute a directory traversal.

n/a n/a n/a CVE