Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-58064

CKEditor is susceptible to Cross-Site Scripting (XSS) through its clipboard package_CVE-2025-58064

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 4...

ckeditor ckeditor5 >= 46.0.0, < 46.0.3 CVE
LOW 3.8 CVE-2025-57146

CVE-2025-57146_CVE-2025-57146

phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.

n/a n/a n/a CVE
LOW 2.1 CVE-2025-41000

Cross-Frame Scripting (XFS) in BoomCMS_CVE-2025-41000

Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to s...

BoomCMS BoomCMS 9.1.4 CVE
LOW 2.7 CVE-2025-9821

SSRF via webhook function_CVE-2025-9821

SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request respon...

Mautic Mautic >= 4.4.0 CVE
LOW 2 CVE-2025-58272

CVE-2025-58272_CVE-2025-58272

Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by...

NTT EAST, Inc. Web Caster V130 1.08 and earlier CVE
LOW 3.7 CVE-2025-7039

Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()_CVE-2025-7039

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to poten...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 2.3 CVE-2025-8662

CVE-2025-8662_CVE-2025-8662

OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue aff...

OpenAM consortium OpenAM 14.0.0 CVE
LOW 1.8 CVE-2025-9806

Tenda F1202 Administrative shadow hard-coded credentials_CVE-2025-9806

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the componen...

Tenda F1202 1.2.0.9 CVE
LOW 1.3 CVE-2025-58161

MobSF Path Traversal in GET /download/ using absolute filenames_CVE-2025-58161

MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.comm...

MobSF Mobile-Security-Framework-MobSF = 4.4.0 CVE
LOW 2.3 CVE-2025-9799

Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery_CVE-2025-9799

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file ...

n/a Langfuse 3.0 CVE