Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2026-22712

ApprovedRevs allows bypassing the inline CSS sanitizer_CVE-2026-22712

Improper Encoding or Escaping of Output due to magic word replacement in ParserAfterTidy vulnerability in The Wikimedia Foundation Mediawiki - Appr...

The Wikimedia Foundation Mediawiki - ApprovedRevs Extension 1.45 CVE
LOW 3.3 CVE-2026-0747

CVE-2026-0747_CVE-2026-0747

Exposure of sensitive information in the TeamViewer entry dashboard component in Devolutions Remote Desktop Manager 2025.3.24.0 through 2025.3.28.0...

Devolutions Remote Desktop Manager 2025.3.24.0 CVE
LOW 2.7 CVE-2026-21895

rsa crate has potential panic on a prime being equal to 1_CVE-2026-21895

The `rsa` crate is an RSA implementation written in rust. Prior to version 0.9.10, when creating a RSA private key from its components, the constru...

RustCrypto RSA < 0.9.10 CVE
LOW 2 CVE-2026-22041

loggingredactor converts non-string types to string types in logs_CVE-2026-22041

Logging Redactor is a Python library designed to redact sensitive data in logs based on regex patterns and / or dictionary keys. Prior to version 0...

armurox loggingredactor < 0.0.6 CVE
LOW 3.1 CVE-2025-15224

libssh key passphrase bypass without agent set_CVE-2025-15224

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate u...

curl curl 8.17.0 CVE
LOW 1.8 CVE-2025-12776

Stored Cross-Site Scripting_CVE-2025-12776

The Report Builder component of the application stores user input directly in a web page and displays it to other users, which raised concerns abou...

Commvault WebConsole 11.32.0 CVE
LOW 1.9 MS:CVE-2025-11961

OOBR and OOBW in pcap_ether_aton() in libpcap_MS:CVE-2025-11961

{“lastseen”:”2026-01-06T09:42:33″,”description”:””,”published”:”2026-01-03T01:01:...

N/A N/A MSCVE
LOW 1.9 MS:CVE-2025-11964

OOBW in utf_16le_to_utf_8_truncated() in libpcap_MS:CVE-2025-11964

{“lastseen”:”2026-01-06T09:42:33″,”description”:””,”published”:”2026-01-03T01:01:...

N/A N/A MSCVE
LOW 2.9 CVE-2025-31963

HCL BigFix IVR is impacted by improper authentication and missing CSRF protection_CVE-2025-31963

Improper authentication and missing CSRF protection in the local setup interface component in HCL BigFix IVR version 4.2 allows a local attacker to...

HCLSoftware BigFix IVR 4.2 CVE
LOW 2.2 CVE-2025-31964

HCL BigFix IVR is impacted by an improper service binding configuration_CVE-2025-31964

Improper service binding configuration in internal service components in HCL BigFix IVR version 4.2 allows a privileged attacker to impact service ...

HCLSoftware BigFix IVR 4.2 CVE