Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2025-53857

Lack of Authorization on Get Channel Subscriptions for Autocomplete in Mattermost Confluence Plugin_CVE-2025-53857

Mattermost Confluence Plugin version

Mattermost Mattermost Confluence Plugin CVE
LOW 3.3 CVE-2025-24925

applications_settings has a missing release of memory vulnerability_CVE-2025-24925

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

OpenHarmony OpenHarmony v5.0.3 CVE
LOW 3.3 CVE-2025-26690

communication dsoftbus has a NULL pointer vulnerability_CVE-2025-26690

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.

OpenHarmony OpenHarmony v5.0.3 CVE
LOW 3.3 CVE-2025-27536

arkcompiler_ets_runtime has a type confusion vulnerability_CVE-2025-27536

in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through type confusion.

OpenHarmony OpenHarmony v5.0.3 CVE
LOW 3.3 CVE-2025-24844

communication_dsoftbus has a missing release of memory vulnerability_CVE-2025-24844

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

OpenHarmony OpenHarmony v5.0.3 CVE
LOW 3.3 CVE-2025-25212

pasteboard has an improper input vulnerability_CVE-2025-25212

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through improper input.

OpenHarmony OpenHarmony v5.0.3 CVE
LOW 3.3 CVE-2025-27562

communication_dsoftbus has a missing release of memory vulnerability_CVE-2025-27562

in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.

OpenHarmony OpenHarmony v5.0.3 CVE
LOW 3.5 THN:8E6882EAF31...

Researchers Detail Windows EPM Poisoning Exploit Chain Leading to Domain Privilege Escalation_THN:8E6882EAF31BB9C5BE174E1FE1B38EA7

![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=) Cybersecurity researchers ...

N/A N/A THN
LOW 3 CVE-2025-52136

CVE-2025-52136_CVE-2025-52136

In EMQX before 5.8.6, administrators can install arbitrary novel plugins via the Dashboard web interface. NOTE: the Supplier's position is that thi...

EMQX EMQX CVE
LOW 2 CVE-2025-8774

riscv-boom SonicBOOM L1 Data Cache timing discrepancy_CVE-2025-8774

A vulnerability has been found in riscv-boom SonicBOOM up to 2.2.3 and classified as problematic. Affected by this vulnerability is an unknown func...

riscv-boom SonicBOOM 2.2.0 CVE