Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.5 CVE-2025-3950

Exposure of Private Personal Information to an Unauthorized Actor in GitLab_CVE-2025-3950

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that coul...

GitLab GitLab 10.3 CVE
LOW 2.1 CVE-2026-20975

CVE-2026-20975_CVE-2026-20975

Improper handling of insufficient permission in Samsung Cloud prior to version 5.6.11 allows local attackers to access specific files in arbitrary ...

Samsung Mobile Samsung Cloud 5.6.11 CVE
LOW 2.3 CVE-2026-20969

CVE-2026-20969_CVE-2026-20969

Improper input validation in SecSettings prior to SMR Jan-2026 Release 1 allows local attacker to access file with system privilege. User interacti...

Samsung Mobile Samsung Mobile Devices SMR Jan-2026 Release in Selected Android 13, 14, 15, 16 devices CVE
LOW 2.3 CVE-2026-22710

Stored XSS through autocomment system messages in Wikibase_CVE-2026-22710

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - W...

The Wikimedia Foundation Mediawiki - Wikibase Extension 1.45 CVE
LOW 2.3 CVE-2026-22714

i18n XSS, DoS and config SQLI in Monaco_CVE-2026-22714

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - M...

The Wikimedia Foundation Mediawiki - Monaco Skin 1.45 CVE
LOW 2.3 CVE-2026-22713

Stored XSS through edit summaries in GrowthExperiments_CVE-2026-22713

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - G...

The Wikimedia Foundation Mediawiki - GrowthExperiments Extension 1.45 CVE
LOW 2.3 CVE-2026-22712

ApprovedRevs allows bypassing the inline CSS sanitizer_CVE-2026-22712

Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - Appr...

The Wikimedia Foundation Mediawiki - ApprovedRevs Extension 1.45 CVE
LOW 3.3 CVE-2026-0747

CVE-2026-0747_CVE-2026-0747

Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0...

Devolutions Remote Desktop Manager 2025.3.24.0 CVE
LOW 2.7 CVE-2026-21895

rsa crate has potential panic on a prime being equal to 1_CVE-2026-21895

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the constru...

RustCrypto RSA < 0.9.10 CVE
LOW 2 CVE-2026-22041

loggingredactor converts non-string types to string types in logs_CVE-2026-22041

Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictionary keys. Prior to version 0...

armurox loggingredactor < 0.0.6 CVE