Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-61738

Johnson Controls PowerG and IQPanel cleartext transmission of sensitive information_CVE-2025-61738

Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.

Johnson Controls IQPanel2, IQHub,IQPanel2+,IQPanel 4,PowerG IQPanel2 CVE
LOW 2.7 CVE-2025-12654

Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.120 - Authenticated (Admin+) Arbitrary Directory Creation_CVE-2025-12654

The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to arbitrary directory creation in all versions up t...

wpvividplugins Migration, Backup, Staging – WPvivid Backup & Migration * CVE
LOW 1.3 CVE-2025-53922

Galette has access control bypass_CVE-2025-53922

Galette is a membership management web application for non profit organizations. Starting in version 1.1.4 and prior to version 1.2.0, a user who i...

galette galette >= 1.1.4, < 1.2.0 CVE
LOW 2.3 CVE-2025-14953

Open5GS FAR-ID handler.c ogs_pfcp_handle_create_pdr null pointer dereference_CVE-2025-14953

A flaw has been found in Open5GS up to 2.7.5. This impacts the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the compone...

n/a Open5GS 2.7.0 CVE
LOW 2.1 CVE-2025-58052

Galette has groups managers access control bypass on Members_CVE-2025-58052

Galette is a membership management web application for non profit organizations. Starting in version 0.9.6 and prior to version 1.2.0, attackers wi...

galette galette >= 0.9.6, < 1.2.0 CVE
LOW 1.7 CVE-2025-68457

Orejime has executable code in HTML attributes_CVE-2025-68457

Orejime is a consent manager that focuses on accessibility. On HTML elements handled by Orejime prior to version 2.3.2, one could run malicious cod...

boscop-fr orejime < 2.3.2 CVE
LOW 3.8 CVE-2025-14882

Insecure direct object reference_CVE-2025-14882

An API endpoint allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible by UUID ...

pretix pretix-offlinesales 1.12.0 CVE
LOW 3.8 CVE-2025-14881

Insecure direct object reference_CVE-2025-14881

Multiple API endpoints allowed access to sensitive files from other users by knowing the UUID of the file that were not intended to be accessible b...

pretix pretix 1.0.0 CVE
LOW 3.1 MS:CVE-2025-65046

Microsoft Edge (Chromium-based) Spoofing Vulnerability_MS:CVE-2025-65046

{“lastseen”:”2025-12-18T23:36:40″,”description”:””,”published”:”2025-12-18T08:00:...

N/A N/A MSCVE
LOW 3.1 CVE-2025-65046

Microsoft Edge (Chromium-based) Spoofing Vulnerability_CVE-2025-65046

{“lastseen”:””,”description”:””,”published”:”2025-12-18T22:01:43.462Z”,&#82...

Microsoft Microsoft Edge for Android 1.0.0 CVE