Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.5 CVE-2025-13758

CVE-2025-13758_CVE-2025-13758

Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, through 2025.3.8.

Devolutions Server CVE
LOW 1 CVE-2025-6666

motogadget mo.lock Ignition Lock NFC hard-coded key_CVE-2025-6666

A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of th...

motogadget mo.lock Ignition Lock 20251125 CVE
LOW 3.3 CVE-2025-65681

CVE-2025-65681_CVE-2025-65681

An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive...

n/a n/a n/a CVE
LOW 2.9 CVE-2025-66382

CVE-2025-66382_CVE-2025-66382

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

libexpat project libexpat CVE
LOW 2.8 CVE-2025-66372

CVE-2025-66372_CVE-2025-66372

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

mustangproject Mustang CVE
LOW 2.4 CVE-2025-13742

Limited HTML injection in emails_CVE-2025-13742

Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it wi...

pretix pretix 1.0.0 CVE
LOW 3.7 CVE-2025-2486

UEFI Shell accessible in AAVMF with Secure Boot enabled on Ubuntu_CVE-2025-2486

The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, possibly allowing bypass of ...

Ubuntu edk2 2024.05 CVE
LOW 2.7 CVE-2025-20373

Sensitive Information Disclosure in “_internal“ index through Splunk Add-On for Palo Alto Networks_CVE-2025-20373

In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _internal index during the add...

Splunk Splunk Add-on for Palo Alto Networks 2.0 CVE
LOW 2 CVE-2025-13611

Insertion of Sensitive Information into Log File in GitLab_CVE-2025-13611

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that coul...

GitLab GitLab 13.2 CVE
LOW 3.6 CVE-2025-66040

Spotipy has a XSS vulnerability in OAuth callback server_CVE-2025-66040

Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vulnerability in the OAuth call...

spotipy-dev spotipy < 2.25.2 CVE