Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1 CVE-2025-8052

HQL Injection vulnerability has been discovered in Opentext Flipper._CVE-2025-8052

SQL Injection vulnerability in opentext Flipper allows SQL Injection.  The vulnerability could allow a low privilege user to interact with the dat...

opentext Flipper 3.1.2 CVE
LOW 2.9 CVE-2025-57837

CVE-2025-57837_CVE-2025-57837

Tileservice module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect service confidentiality.

Honor FCP-AN10 8.0 CVE
LOW 2 CVE-2025-11947

bftpd Configuration File options.c expand_groups heap-based overflow_CVE-2025-11947

A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the component Configuration File...

n/a bftpd 6.0 CVE
LOW 2 CVE-2025-62653

Stored XSS through system messages in PollNY_CVE-2025-62653

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki Pol...

The Wikimedia Foundation MediaWiki PollNY extension 1.39 CVE
LOW 2 CVE-2025-62654

Stored XSS through system messages in QuizGame_CVE-2025-62654

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation MediaWiki Qui...

The Wikimedia Foundation MediaWiki QuizGame extension 1.39 CVE
LOW 2.1 CVE-2025-62655

SQL injection in Cargo via Special:CargoExport_CVE-2025-62655

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation MediaWiki Cargo exte...

The Wikimedia Foundation MediaWiki Cargo extension 1.39 CVE
LOW 3.4 CVE-2025-62643

CVE-2025-62643_CVE-2025-62643

The Restaurant Brands International (RBI) assistant platform through 2025-09-06 transmits passwords of user accounts in cleartext e-mail messages.

Restaurant Brands International assistant platform CVE
LOW 3 CVE-2025-62505

SSRF in lobehub/lobe-chat with native web fetch module_CVE-2025-62505

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF)...

lobehub lobe-chat < 1.136.2 CVE
LOW 2 CVE-2025-58747

Dify MCP OAuth Flow Vulnerable to XSS_CVE-2025-58747

Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable to cross-site scripting when...

langgenius dify <= 1.9.1 CVE
LOW 2.8 CVE-2025-60361

CVE-2025-60361_CVE-2025-60361

radare2 v5.9.8 and before contains a memory leak in the function bochs_open.

n/a n/a n/a CVE