Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.5 CVE-2025-27550

IBM Jazz Reporting Service Information Disclosure_CVE-2025-27550

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside o...

IBM Jazz Reporting Service 7.1 CVE
LOW 3.5 CVE-2025-1823

IBM Jazz Reporting Service Denial of Service_CVE-2025-1823

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query tha...

IBM Jazz Reporting Service 7.1 CVE
LOW 2.3 CVE-2026-1892

WeKan REST API boards.js setBoardOrgs improper authorization_CVE-2026-1892

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the componen...

n/a WeKan 8.0 CVE
LOW 3.1 CVE-2026-20732

BIG-IP Configuration utility vulnerability_CVE-2026-20732

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software vers...

F5 BIG-IP 21.0.0 CVE
LOW 3.3 CVE-2026-20730

BIG-IP Edge Client for Windows vulnerability_CVE-2026-20730

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information.  ...

F5 BIG-IP Edge Client 7.2.5 CVE
LOW 2.7 CVE-2026-1791

Arbitrary File Upload Vulnerability in Operation and Maintenance Security Gateway_CVE-2026-1791

Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Uplo...

Hillstone Networks Operation and Maintenance Security Gateway V5.5ST00001B113 CVE
LOW 3.1 CVE-2026-24513

ingress-nginx auth-url protection bypass_CVE-2026-24513

A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the pre...

Kubernetes ingress-nginx CVE
LOW 3.7 CVE-2026-25224

Fastify Vulnerable to DoS via Unbounded Memory Allocation in sendWebStream_CVE-2026-25224

Fastify is a fast and low overhead web framework, for Node.js. Prior to version 5.7.3, a denial-of-service vulnerability in Fastify’s Web Streams r...

fastify fastify < 5.7.3 CVE
LOW 2.7 CVE-2026-25149

Qwik City Open Redirect via fixTrailingSlash_CVE-2026-25149

Qwik is a performance focused javascript framework. Prior to version 1.19.0, an Open Redirect vulnerability in Qwik City's default request handler ...

QwikDev qwik < 1.19.0 CVE
LOW 3.1 CVE-2025-52633

HCL AION is susceptible to Missing Content-Security-Policy_CVE-2025-52633

HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persiste...

HCL AION 2.0 CVE