Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-15124

JeecgBoot list getParameterMap improper authorization_CVE-2025-15124

A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The m...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15125

JeecgBoot queryDepartPermission improper authorization_CVE-2025-15125

A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepar...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15126

JeecgBoot getPositionUserList improper authorization_CVE-2025-15126

A weakness has been identified in JeecgBoot up to 3.9.0. Affected by this vulnerability is the function getPositionUserList of the file /sys/positi...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15120

JeecgBoot getDeptRoleList improper authorization_CVE-2025-15120

A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manip...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15122

JeecgBoot datarule loadDatarule improper authorization_CVE-2025-15122

A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Per...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15123

JeecgBoot datarule improper authorization_CVE-2025-15123

A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing...

n/a JeecgBoot 3.0 CVE
LOW 2.3 CVE-2025-15117

Dromara Sa-Token SaJdkSerializer.java ObjectInputStream.readObject deserialization_CVE-2025-15117

A weakness has been identified in Dromara Sa-Token up to 1.44.0. This affects the function ObjectInputStream.readObject of the file SaJdkSerializer...

Dromara Sa-Token 1.0 CVE
LOW 2.3 CVE-2025-15119

JeecgBoot list queryPageList improper authorization_CVE-2025-15119

A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manip...

n/a JeecgBoot 3.0 CVE
LOW 2.9 CVE-2025-68932

FreshRSS has weak cryptographic randomness in remember-me token and nonce generation_CVE-2025-68932

FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random number generators (mt_rand()...

FreshRSS FreshRSS < 1.28.0 CVE
LOW 3.1 CVE-2025-36229

Exposure of Sensitive System Information to an Unauthorized Control Sphere in IBM Aspera Faspex_CVE-2025-36229

IBM Aspera Faspex 5 5.0.0 through 5.0.14.1 could allow authenticated users to enumerate sensitive information of data due by enumerating package id...

IBM Aspera Faspex 5 5.0.0 CVE