Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1 CVE-2025-13912

Potential non-constant time compiled code with Clang LLVM_CVE-2025-13912

Multiple constant-time implementations in wolfSSL before version 5.8.4 may be transformed into non-constant-time binary by LLVM optimizations, whic...

wolfSSL wolfSSL CVE
LOW 3.8 CVE-2025-67742

CVE-2025-67742_CVE-2025-67742

In JetBrains TeamCity before 2025.11 path traversal was possible via file upload

JetBrains TeamCity CVE
LOW 2.7 CVE-2025-67740

CVE-2025-67740_CVE-2025-67740

In JetBrains TeamCity before 2025.11 improper access control could expose GitHub App token's metadata

JetBrains TeamCity CVE
LOW 3.1 CVE-2025-67739

CVE-2025-67739_CVE-2025-67739

In JetBrains TeamCity before 2025.11.2 improper repository URL validation could lead to local paths disclosure

JetBrains TeamCity CVE
LOW 3.5 CVE-2025-12734

Improper Encoding or Escaping of Output in GitLab_CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that coul...

GitLab GitLab 15.6 CVE
LOW 2.3 CVE-2025-14485

EFM ipTIME A3004T Administrator Password timepro.cgi show_debug_screen command injection_CVE-2025-14485

A weakness has been identified in EFM ipTIME A3004T 14.19.0. This vulnerability affects the function show_debug_screen of the file /sess-bin/timepr...

EFM ipTIME A3004T 14.19.0 CVE
LOW 3.5 CVE-2025-67646

TableProgressTracking’s missing CSRF protection allows unauthorized state changes_CVE-2025-67646

TableProgressTracking is a MediaWiki extension to track progress against specific criterion. Versions 1.2.0 and below do not enforce CSRF token val...

Telepedia TableProgressTracking < 1.2.1 CVE
LOW 3.5 CVE-2025-67639

CVE-2025-67639_CVE-2025-67639

A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and earlier, LTS 2.528.2 and earlier allows attackers to trick users into loggin...

Jenkins Project Jenkins 2.541 CVE
LOW 1.9 CVE-2025-5467

Ubuntu Apport Insecure File Permissions Vulnerability_CVE-2025-5467

It was discovered that process_crash() in data/apport in Canonical's Apport crash reporting tool may create crash files with incorrect group owners...

Canonical apport 2.20.11-0ubuntu82 CVE
LOW 3.5 CVE-2025-13127

XSS in TACAS Consulting’s GoldenHorn_CVE-2025-13127

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and ...

TAC Information Services Internal and External Trade Inc. GoldenHorn CVE