Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 1.8 CVE-2025-54821

CVE-2025-54821_CVE-2025-54821

An Improper Privilege Management vulnerability [CWE-269] in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all version...

Fortinet FortiProxy 7.6.0 CVE
LOW 3.7 CVE-2025-13083

Drupal core – Moderately critical – Information disclosure – SA-CORE-2025-008_CVE-2025-13083

Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrectly Configured Access Contr...

Drupal Drupal core 8.0.0 CVE
LOW 3.5 CVE-2025-12761

Simple multi step form – Moderately critical – Cross-site Scripting – SA-CONTRIB-2025-116_CVE-2025-12761

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple multi step form allows Cross-Si...

Drupal Simple multi step form 0.0.0 CVE
LOW 3.5 CVE-2025-52639

HCL Connections is vulnerable to sensitive information disclosure_CVE-2025-52639

HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sensitive information they are...

HCL Software Connections 8.0 CVE
LOW 3.7 CVE-2025-65014

LibreNMS has Weak Password Policy_CVE-2025-65014

LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password policy vulnerability was id...

librenms librenms < 25.11.0 CVE
LOW 3.2 CVE-2025-12792

CVE-2025-12792_CVE-2025-12792

The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A local threat actor with unpriv...

Canva Canva CVE
LOW 2.4 CVE-2025-64734

CVE-2025-64734_CVE-2025-64734

Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access to the Reader to perform a...

Gallagher T21 Reader CVE
LOW 3.2 CVE-2025-65083

CVE-2025-65083_CVE-2025-65083

GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be problematic if the GoSign Deskt...

Tinexta Infocert GoSign Desktop CVE
LOW 2.3 CVE-2025-60022

CVE-2025-60022_CVE-2025-60022

Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerability is exploited, a man...

KDDI CORPORATION 'デジラアプリ' App for iOS prior to ver.80.10.00 CVE
LOW 3.1 CVE-2025-7736

Incorrect Authorization in GitLab_CVE-2025-7736

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that coul...

GitLab GitLab 17.9 CVE