Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2025-62717

Emlog Pro session verification code error due to clearing logic error_CVE-2025-62717

Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification code error due to a clearing ...

emlog emlog = 2.5.23 CVE
LOW 2.1 CVE-2025-62711

Wasmtime vulnerable to segfault when using component resources_CVE-2025-62711

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampol...

bytecodealliance wasmtime >= 38.0.0, < 38.0.3 CVE
LOW 2 CVE-2025-62255

CVE-2025-62255_CVE-2025-62255

Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.4.3.101, and older unsuppor...

Liferay Portal 7.4.0 CVE
LOW 2.3 CVE-2025-11966

CVE-2025-11966_CVE-2025-11966

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into gene...

Eclipse Foundation Vert.x 4.0.0 CVE
LOW 2.1 CVE-2025-62659

The CookieConsent extension does not properly use reserved data attributes, thus introducing potential XSS vectors_CVE-2025-62659

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki Coo...

The Wikimedia Foundation MediaWiki CookieConsent extension v2.0.0 CVE
LOW 2 CVE-2025-62247

CVE-2025-62247_CVE-2025-62247

Missing Authorization in Collection Provider component in the Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.9, ...

Liferay Portal 7.4.0 CVE
LOW 2.6 CVE-2025-62710

Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl_CVE-2025-62710

Sakai is a Collaboration and Learning Environment. Prior to versions 23.5 and 25.0, EncryptionUtilityServiceImpl initialized an AES256TextEncryptor...

sakaiproject sakai < 23.5 CVE
LOW 3.1 CVE-2025-62774

CVE-2025-62774_CVE-2025-62774

On Mercku M6a devices through 2.1.0, the authentication system uses predictable session tokens based on timestamps.

Mercku M6a CVE
LOW 2.4 CVE-2025-62773

CVE-2025-62773_CVE-2025-62773

Mercku M6a devices through 2.1.0 allow TELNET sessions via a router.telnet.enabled.update request by an administrator.

Mercku M6a CVE
LOW 3.1 CVE-2025-62772

CVE-2025-62772_CVE-2025-62772

On Mercku M6a devices through 2.1.0, session tokens remain valid for at least months in some cases.

Mercku M6a CVE