Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.8 CVE-2025-58827

WordPress Job Board Manager Plugin <= 2.1.61 - Content Injection Vulnerability_CVE-2025-58827

Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager allows Code Injection. This issue affects ...

PickPlugins Job Board Manager n/a CVE
LOW 3.5 CVE-2025-58816

WordPress Product Carousel Slider for Elementor Plugin <= 2.1.3 - Broken Access Control Vulnerability_CVE-2025-58816

Missing Authorization vulnerability in Plugin Devs Product Carousel Slider for Elementor allows Exploiting Incorrectly Configured Access Control Se...

Plugin Devs Product Carousel Slider for Elementor n/a CVE
LOW 3.3 CVE-2025-26461

CVE-2025-26461_CVE-2025-26461

In Permission Manager, there is a possible way for the microphone privacy indicator to remain activated even after the user attempts to close the a...

Google Android 16 CVE
LOW 3.8 CVE-2025-57807

ImageMagick BlobStream Forward-Seek Under-Allocation_CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include inse...

ImageMagick ImageMagick < 14.8.2 CVE
LOW 2.7 CVE-2025-10043

Keycloak: incomplete fix of cve-2024-10492_CVE-2025-10043

A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous fix for CVE-2024-10492 did not account for the Wi...

Red Hat Red Hat Build of Keycloak CVE
LOW 2.3 CVE-2025-10014

elunez eladmin Email Address updateEmail updateUserEmail improper authorization_CVE-2025-10014

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component E...

elunez eladmin 2.0 CVE
LOW 3.3 CVE-2025-0076

CVE-2025-0076_CVE-2025-0076

In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check. This could lead to local ...

Google Android 15 CVE
LOW 2.7 CVE-2025-58866

WordPress Site Info Plugin <= 1.1 - Sensitive Data Exposure Vulnerability_CVE-2025-58866

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info allows Retrieve Embedded Sensi...

Rami Yushuvaev Site Info n/a CVE
LOW 2.1 CVE-2025-58352

Weblate has long session expiry times during second factor verification_CVE-2025-58352

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second fac...

WeblateOrg weblate < 5.13.1 CVE
LOW 3.2 CVE-2025-26428

CVE-2025-26428_CVE-2025-26428

In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physic...

Google Android 15 CVE