Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.7 CVE-2025-66629

HedgeDoc is missing state parameter in OAuth2 flows could lead to CSRF_CVE-2025-66629

HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to 1.10.4, some of HedgeDoc's OAuth2 endpoints for social l...

hedgedoc hedgedoc < 1.10.4 CVE
LOW 2.1 MS:CVE-2025-13837

Out-of-memory when loading Plist_MS:CVE-2025-13837

{“lastseen”:”2025-12-05T19:40:21″,”description”:””,”published”:”2025-12-05T01:03:...

N/A N/A MSCVE
LOW 3.5 MS:CVE-2025-13640

Chromium: CVE-2025-13640 Inappropriate implementation in Passwords_MS:CVE-2025-13640

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Rel...

N/A N/A MSCVE
LOW 2 CVE-2025-14007

dayrui XunRuiCMS Domain Name Binding admin79f2ec220c7e.php cross site scripting_CVE-2025-14007

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mob...

dayrui XunRuiCMS 4.7.0 CVE
LOW 2.2 CVE-2025-12997

CVE-2025-12997_CVE-2025-12997

Insecure Direct Object Reference vulnerability in Medtronic CareLink Network which allows an authenticated attacker with access to specific device ...

Medtronic CareLink Network CVE
LOW 1.8 CVE-2025-66479

Anthropic Sandbox Runtime Incorrectly Implemented Network Sandboxing_CVE-2025-66479

Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level...

anthropic-experimental sandbox-runtime < 0.0.16 CVE
LOW 2.7 CVE-2025-12954

Timetable and Event Schedule by MotoPress < 2.4.16 - Contributor+ Event Disclosure via IDOR_CVE-2025-12954

The Timetable and Event Schedule by MotoPress WordPress plugin before 2.4.16 does not verify a user has access to a specific event when duplicating...

Unknown Timetable and Event Schedule by MotoPress CVE
LOW 1.3 CVE-2025-13751

CVE-2025-13751_CVE-2025-13751

Interactive service agent in OpenVPN version 2.5.0 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigg...

OpenVPN OpenVPN 2.5.0 CVE
LOW 2.7 CVE-2025-20388

Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise_CVE-2025-20388

In Splunk Enterprise versions below 10.0.1, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.4, 10.0.2503.7, and 9.3.24...

Splunk Splunk Enterprise 10.0 CVE
LOW 2.4 CVE-2025-20385

Stored Cross-Site scripting (XSS) through Anchor Tag “href” in Navigation Bar Collections in Splunk Enterprise_CVE-2025-20385

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform versions below 10.1.2507.6, 10.0.2503.7, and 9.3.24...

Splunk Splunk Enterprise 10.0 CVE