Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2025-59163

vet MCP Server SSE Transport DNS Rebinding Vulnerability_CVE-2025-59163

vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP H...

safedep vet < 1.12.5 CVE
LOW 3.3 CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes session token in debug output_CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to s...

Medical Informatics Engineering Enterprise Health RC202503 CVE
LOW 3.4 CVE-2025-35032

Medical Informatics Engineering Enterprise Health arbitrary file upload_CVE-2025-35032

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how ...

Medical Informatics Engineering Enterprise Health CVE
LOW 3.3 CVE-2025-36144

IBM watsonx.data information disclosure_CVE-2025-36144

IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

IBM watsonx.data 2.2 CVE
LOW 2.1 CVE-2025-59842

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute_CVE-2025-59842

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4....

jupyterlab jupyterlab < 4.4.8 CVE
LOW 3.7 CVE-2025-36326

IBM Controller information disclosure_CVE-2025-36326

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due t...

IBM Cognos Controller 11.0.0 CVE
LOW 3.8 CVE-2025-10871

Missing Authorization in GitLab_CVE-2025-10871

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maint...

GitLab GitLab 16.6 CVE
LOW 3.5 CVE-2025-10867

Allocation of Resources Without Limits or Throttling in GitLab_CVE-2025-10867

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could ...

GitLab GitLab 18.1 CVE
LOW 3.5 CVE-2025-10868

Business Logic Errors in GitLab_CVE-2025-10868

An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certa...

GitLab GitLab 17.4 CVE
LOW 3.5 CVE-2025-5069

Incorrect Ownership Assignment in GitLab_CVE-2025-5069

An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could...

GitLab GitLab 17.10 CVE