Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1.9 CVE-2025-11964

OOBW in utf_16le_to_utf_8_truncated() in libpcap_CVE-2025-11964

On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 byt...

The Tcpdump Group libpcap 1.10.0 CVE
LOW 1.9 CVE-2025-11961

OOBR and OOBW in pcap_ether_aton() in libpcap_CVE-2025-11961

pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument m...

The Tcpdump Group libpcap CVE
LOW 1.3 CVE-2025-14986

ExecuteMultiOperation Namespace Policy Bypass_CVE-2025-14986

When frontend.enableExecuteMultiOperation is enabled, the server can apply namespace-scoped validation and feature gates for the embedded StartWork...

Temporal Temporal 1.24.0 CVE
LOW 2.7 CVE-2025-61594

URI Credential Leakage Bypass over CVE-2025-27221_CVE-2025-61594

URI is a module providing classes to handle Uniform Resource Identifiers. In versions prior to 0.12.5, 0.13.3, and 1.0.4, a bypass exists for the f...

ruby uri CVE
LOW 1.2 CVE-2025-69210

FacturaScripts vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload_CVE-2025-69210

FacturaScripts is open-source enterprise resource planning and accounting software. Prior to version 2025.7, a stored cross-site scripting (XSS) vu...

NeoRazorX facturascripts < 2025.7 CVE
LOW 1.3 CVE-2025-67746

Composer vulnerable to ANSI sequence injection_CVE-2025-67746

Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Compos...

composer composer >= 2.0, < 2.2.26 CVE
LOW 3.8 CVE-2025-69015

WordPress Crowdsignal Forms plugin <= 1.7.2 - Broken Access Control vulnerability_CVE-2025-69015

Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Secur...

Automattic Crowdsignal Forms n/a CVE
LOW 2.3 CVE-2025-15242

PHPEMS Coupon race condition_CVE-2025-15242

A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing manipula...

n/a PHPEMS 11.0 CVE
LOW 2.3 CVE-2025-15222

Dromara Sa-Token SaSerializerTemplateForJdkUseBase64.java ObjectInputStream.readObject deserialization_CVE-2025-15222

A vulnerability has been found in Dromara Sa-Token up to 1.44.0. This issue affects the function ObjectInputStream.readObject of the file SaSeriali...

Dromara Sa-Token 1.0 CVE
LOW 2.3 CVE-2025-15141

Halo Configuration actuator information disclosure_CVE-2025-15141

A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configurati...

n/a Halo 2.21.0 CVE