Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.6 22BBAA8D-F2E8-

Exploit for Link Following in 7-Zip_22BBAA8D-F2E8-5CE3-865A-9B091906FF57

🔒 CVE-2025-55188-7z-exploit - Easy Steps to Download and Run 🚀 Getting Started Welcome to CVE-2025-55188-7z-exploit!...

N/A N/A GITHUBEXPLOIT
LOW 2.3 CVE-2025-8448

CVE-2025-8448_CVE-2025-8448

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credenti...

Schneider Eelctric EcoStruxureTM Building Operation Enterprise Server Versions prior to 7.0.1 CVE
LOW 2.7 CVE-2025-2988

IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure_CVE-2025-2988

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive se...

IBM Sterling B2B Integrator 6.0.0.0 CVE
LOW 2.4 CVE-2025-54411

Discourse welcome banner user name XSS_CVE-2025-54411

Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect...

discourse discourse < 3.5.0.beta8 CVE
LOW 2 CVE-2025-3639

CVE-2025-3639_CVE-2025-3639

Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024....

Liferay Portal 7.3.0 CVE
LOW 2.2 CVE-2025-54234

ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)_CVE-2025-54234

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limi...

Adobe ColdFusion CVE
LOW 2.3 CVE-2025-43733

CVE-2025-43733_CVE-2025-43733

A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.3.132, and Liferay DXP 2025.Q1.0 through 2025.Q1.7 allows a remote a...

Liferay Portal 7.4.3.132 CVE
LOW 2 CVE-2025-9091

Tenda AC20 shadow hard-coded credentials_CVE-2025-9091

A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is an unknown functionality of the file /etc_ro/shado...

Tenda AC20 16.03.08.12 CVE
LOW 1 CVE-2025-9092

Hybrid Module Deployment in Multi-JVM Environments Leading to Resource Exhaustion_CVE-2025-9092

Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 bc-fips (API modules) all...

Legion of the Bouncy Castle Inc. Bouncy Castle for Java - BC-FJA 2.1.0 BC-FJA 2.1.0 CVE
LOW 2.6 CVE-2025-55285

@backstage/plugin-scaffolder-backend Template Secret Leakage in Logs in Scaffolder When Using `fetch:template`_CVE-2025-55285

@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. Prior to version 2.1.1, duplicate logging of the ...

backstage backstage < 2.1.1 CVE