Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.5 CVE-2025-12761

Simple multi step form – Moderately critical – Cross-site Scripting – SA-CONTRIB-2025-116_CVE-2025-12761

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple multi step form allows Cross-Si...

Drupal Simple multi step form 0.0.0 CVE
LOW 3.5 CVE-2025-52639

HCL Connections is vulnerable to sensitive information disclosure_CVE-2025-52639

HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are...

HCL Software Connections 8.0 CVE
LOW 3.7 CVE-2025-65014

LibreNMS has Weak Password Policy_CVE-2025-65014

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was id...

librenms librenms < 25.11.0 CVE
LOW 3.2 CVE-2025-12792

CVE-2025-12792_CVE-2025-12792

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unpriv...

Canva Canva CVE
LOW 2.4 CVE-2025-64734

CVE-2025-64734_CVE-2025-64734

Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access to the Reader to perform a...

Gallagher T21 Reader CVE
LOW 3.2 CVE-2025-65083

CVE-2025-65083_CVE-2025-65083

GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Deskt...

Tinexta Infocert GoSign Desktop CVE
LOW 2.3 CVE-2025-60022

CVE-2025-60022_CVE-2025-60022

Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man...

KDDI CORPORATION 'デジラアプリ' App for iOS prior to ver.80.10.00 CVE
LOW 3.1 CVE-2025-7736

Incorrect Authorization in GitLab_CVE-2025-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that coul...

GitLab GitLab 17.9 CVE
LOW 3.5 CVE-2025-6945

Improper Neutralization of Special Elements used in a Command (‘Command Injection’) in GitLab_CVE-2025-6945

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could h...

GitLab GitLab 17.8 CVE
LOW 3.1 CVE-2025-11990

Improper Handling of URL Encoding (Hex Encoding) in GitLab_CVE-2025-11990

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authe...

GitLab GitLab 18.4 CVE