Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2025-6601

Business Logic Errors in GitLab_CVE-2025-6601

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions co...

GitLab GitLab 18.4 CVE
LOW 2.1 CVE-2025-12221

CSRF Token not Properly Implemented_CVE-2025-12221

Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Azure Access Technology BLU-IC2 CVE
LOW 2.7 CVE-2025-11888

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update_CVE-2025-11888

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modificatio...

roxnor ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution * CVE
LOW 3.7 CVE-2025-11244

Password Protected <= 2.7.11 - Unauthenticated Authorization Bypass via IP Address Spoofing_CVE-2025-11244

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7...

saadiqbal Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content * CVE
LOW 2.7 CVE-2025-10723

PixelYourSite < 11.1.2 - Admin+ LFI_CVE-2025-10723

The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, a...

Unknown PixelYourSite CVE
LOW 2.7 CVE-2025-62717

Emlog Pro session verification code error due to clearing logic error_CVE-2025-62717

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing ...

emlog emlog = 2.5.23 CVE
LOW 2.1 CVE-2025-62711

Wasmtime vulnerable to segfault when using component resources_CVE-2025-62711

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampol...

bytecodealliance wasmtime >= 38.0.0, < 38.0.3 CVE
LOW 2 CVE-2025-62255

CVE-2025-62255_CVE-2025-62255

Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsuppor...

Liferay Portal 7.4.0 CVE
LOW 2.3 CVE-2025-11966

CVE-2025-11966_CVE-2025-11966

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into gene...

Eclipse Foundation Vert.x 4.0.0 CVE
LOW 2.1 CVE-2025-62659

The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors_CVE-2025-62659

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki Coo...

The Wikimedia Foundation MediaWiki CookieConsent extension v2.0.0 CVE