Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.2 CVE-2025-54234

ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)_CVE-2025-54234

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limi...

Adobe ColdFusion CVE
LOW 2.3 CVE-2025-43733

CVE-2025-43733_CVE-2025-43733

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote a...

Liferay Portal 7.4.3.132 CVE
LOW 2 CVE-2025-9091

Tenda AC20 shadow hard-coded credentials_CVE-2025-9091

A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shado...

Tenda AC20 16.03.08.12 CVE
LOW 1 CVE-2025-9092

Hybrid Module Deployment in Multi-JVM Environments Leading to Resource Exhaustion_CVE-2025-9092

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) all...

Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 BC-FJA 2.1.0 CVE
LOW 2.6 CVE-2025-55285

@backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`_CVE-2025-55285

@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the ...

backstage backstage < 2.1.1 CVE
LOW 2 CVE-2025-9020

PX4 PX4-Autopilot Mavlink Shell Closing mavlink_receiver.cpp handle_message_serial_control use after free_CVE-2025-9020

A vulnerability was found in PX4 PX4-Autopilot up to 1.15.4. This issue affects the function MavlinkReceiver::handle_message_serial_control of the ...

PX4 PX4-Autopilot 1.15.0 CVE
LOW 3.8 CVE-2025-8013

Quttera Web Malware Scanner <= 3.5.1.41 - Authenticated (Administrator+) Server-Side Request Forgery_CVE-2025-8013

The Quttera Web Malware Scanner plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.5.1.41 vi...

quttera Quttera Web Malware Scanner * CVE
LOW 2.3 CVE-2025-9019

tcpreplay tcpprep cidr.c mask_cidr6 heap-based overflow_CVE-2025-9019

A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. ...

n/a tcpreplay 4.5.1 CVE
LOW 3.7 CVE-2025-31961

HCL Connections is vulnerable to broken access control_CVE-2025-31961

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

HCL Software Connections 8.0 CVE
LOW 1.3 CVE-2025-53903

The Scratch Channel Has Potential Cross-Site Scripting (XSS) Vulnerability_CVE-2025-53903

The Scratch Channel is a news website that is under development as of time of this writing. The file `/api/users.js` doesn't properly sanitize text...

The-Scratch-Channel the-scratch-channel.github.io < 90b39eb56b27b2bac29001abb1a3cac0964b8ddb CVE