Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2025-66062

WordPress WP YouTube Lyte plugin <= 1.7.28 - Open Redirection vulnerability_CVE-2025-66062

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allows Phishing.This issue affe...

Frank Goossens WP YouTube Lyte n/a CVE
LOW 1.8 CVE-2025-54866

Wazuh installation fails to protected authd.pass on Windows_CVE-2025-54866

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to before 4.13.0, a missing ACL on...

wazuh wazuh >= 4.3.0, < 4.13.0 CVE
LOW 2.9 CVE-2025-65111

SpiceDB’s LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results_CVE-2025-65111

SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to version 1.47.1, if a schema...

authzed spicedb < 1.47.1 CVE
LOW 2.1 CVE-2025-11934

Improper Validation of Signature Algorithm Used in TLS 1.3 CertificateVerify_CVE-2025-11934

Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier on multiple platforms allow...

wolfSSL wolfSSL v5.8.2 CVE
LOW 2.3 CVE-2025-11933

DoS Vulnerability in wolfSSL TLS 1.3 CKS Extension_CVE-2025-11933

Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated a...

wofSSL wolfSSL v5.8.2 CVE
LOW 1 CVE-2025-12888

Constant Time Issue with Xtensa-based ESP32 and X22519_CVE-2025-12888

Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU archit...

wolfSSL wolfSSL 5.8.2 CVE
LOW 2.1 CVE-2025-11931

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt_CVE-2025-11931

Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCh...

wolfSSL wolfSSL 5.8.4 CVE
LOW 2.3 CVE-2025-11932

Timing Side-Channel in PSK Binder Verification_CVE-2025-11932

The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak information about the PSK binder

wolfSSL wolfSSL 5.8.4 CVE
LOW 2.3 CVE-2025-12889

TLS 1.2 Client Can Downgrade Digest Used_CVE-2025-12889

With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest.

wolfSSL wolfSSL 5.8.4 CVE
LOW 1.9 CVE-2025-13425

Denial of Service in OSV-SCALIBR_CVE-2025-13425

A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice when ReadDir returns nil for ...

Google OSV-SCALIBR < 0.3.4 CVE