Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2025-10939

Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console_CVE-2025-10939

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The...

Red Hat Red Hat Build of Keycloak CVE
LOW 3.2 CVE-2025-11248

Sensitive Information Logged_CVE-2025-11248

ZohoCorp ManageEngine Endpoint Central versions prior to 11.4.2528.05 are vulnerable to a sensitive information logging issue. An authenticated use...

Zohocorp ManageEngine Endpoint Central CVE
LOW 2 CVE-2025-32785

Pi-hole Admin Interface vulnerable to persistent XSS on Subscribed lists group management (Adress Field)_CVE-2025-32785

Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application. Pi-hole A...

pi-hole web < 6.3 CVE
LOW 1.2 CVE-2025-62779

Frappe Learning users were able to add HTML through input fields in the Job Form_CVE-2025-62779

Frappe Learning is a learning system that helps users structure their content. In Frappe Learning 2.39.1 and earlier, users were able to add HTML t...

frappe lms <= 2.39.1 CVE
LOW 1.3 CVE-2025-62778

Frappe Learning allowed students to access the Quiz Form via direct URL_CVE-2025-62778

Frappe Learning is a learning management system. A security issue was identified in Frappe Learning 2.39.1 and earlier, where students were able to...

frappe lms <= 2.39.1 CVE
LOW 3.7 CVE-2025-11989

Missing Authorization in GitLab_CVE-2025-11989

GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could...

GitLab GitLab 17.6.0 CVE
LOW 2.7 CVE-2025-6601

Business Logic Errors in GitLab_CVE-2025-6601

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions co...

GitLab GitLab 18.4 CVE
LOW 2.1 CVE-2025-12221

CSRF Token not Properly Implemented_CVE-2025-12221

Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Azure Access Technology BLU-IC2 CVE
LOW 2.7 CVE-2025-11888

ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution <= 4.8.4 - Incorrect Authorization to Authenticated (Editor+) License Status Update_CVE-2025-11888

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable to unauthorized modificatio...

roxnor ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution * CVE
LOW 3.7 CVE-2025-11244

Password Protected <= 2.7.11 - Unauthenticated Authorization Bypass via IP Address Spoofing_CVE-2025-11244

The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all versions up to, and including, 2.7...

saadiqbal Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content * CVE