Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-40891

HTML injection in in Time Machine functionality in Guardian/CMC before 25.5.0_CVE-2025-40891

A Stored HTML Injection vulnerability was discovered in the Time Machine Snapshot Diff functionality due to improper validation of network traffic ...

Nozomi Networks Guardian CVE
LOW 2.3 CVE-2025-65000

Exposure of SSH Private Keys in Remote Alert Handlers (Linux) Rule_CVE-2025-65000

SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk

Checkmk GmbH Checkmk 2.4.0 CVE
LOW 3.2 CVE-2025-68462

CVE-2025-68462_CVE-2025-68462

Freedombox before 25.17.1 does not set proper permissions for the backups-data directory, allowing the reading of dump files of databases.

Debian FreedomBox CVE
LOW 1.7 CVE-2025-66647

RIOT OS has buffer overflow in gnrc_ipv6_ext_frag_reass_CVE-2025-66647

RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded ...

RIOT-OS RIOT < 2025.10 CVE
LOW 3.7 CVE-2025-55254

HCL BigFix Remote Control is vulnerable to a Path-relative stylesheet import (PRSSI)_CVE-2025-55254

Improper management of Path-relative stylesheet import in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow to e...

HCL Software BigFix Remote Control <= 10.1.0.0326 CVE
LOW 3.5 CVE-2025-43533

CVE-2025-43533_CVE-2025-43533

Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in watchOS 26.2, iOS 26.2 and iPadOS 26.2, mac...

Apple tvOS unspecified CVE
LOW 3.1 CVE-2025-43531

CVE-2025-43531_CVE-2025-43531

A race condition was addressed with improved state handling. This issue is fixed in watchOS 26.2, Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26...

Apple iOS and iPadOS unspecified CVE
LOW 2 CVE-2025-68399

ChurchCRM has Stored Cross-Site Scripting (XSS) In GroupEditor.php_CVE-2025-68399

ChurchCRM is an open-source church management system. In versions prior to 6.5.4, there is a Stored Cross-Site Scripting (XSS) vulnerability within...

ChurchCRM CRM < 6.5.4 CVE
LOW 2.8 CVE-2025-65185

CVE-2025-65185_CVE-2025-65185

There is a username enumeration via local user login in Entrinsik Informer v5.10.1 which allows malicious users to enumerate users by entering an O...

n/a n/a n/a CVE
LOW 3.9 CVE-2025-13326

Mattermost Desktop App fails to enable Hardened Runtime when packaged for Mac App Store_CVE-2025-13326

Mattermost Desktop App versions

Mattermost Mattermost CVE