Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.8 CVE-2025-63678

CVE-2025-63678_CVE-2025-63678

An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers ...

n/a n/a n/a CVE
LOW 3.5 CVE-2025-20379

Risky command safeguards bypass using the “/services/streams/search“ REST endpoint through “q“ parameter in Splunk Enterprise_CVE-2025-20379

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.116, 9.3.2408.124, 10.0.2503....

Splunk Splunk Enterprise 10.0 CVE
LOW 3.1 CVE-2025-20378

Open Redirect on Web Login endpoint in Splunk Enterprise_CVE-2025-20378

In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9.3.2411.111, and 9.3.2408.1...

Splunk Splunk Enterprise 10.0 CVE
LOW 3.7 CVE-2025-57812

[BIGSLEEP-434612419] CUPS-Filters has heap-buffer-overflow write in `cfImageLut()`_CVE-2025-57812

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package ...

OpenPrinting libcupsfilters cups-filters <= 1.28.17 CVE
LOW 3.8 CVE-2025-64170

sudo-rs: Partial password reveal is possible after timeout_CVE-2025-64170

sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0.2.10, if a user begins ent...

trifectatechfoundation sudo-rs >= 0.2.7, < 0.2.10 CVE
LOW 1.8 CVE-2025-64345

Wasmtime provides unsound API access to a WebAssembly shared linear memory_CVE-2025-64345

Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API contains an unsound intera...

bytecodealliance wasmtime >= 38.0.1, < 38.0.4 CVE
LOW 2.7 CVE-2025-64773

CVE-2025-64773_CVE-2025-64773

In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit

JetBrains YouTrack CVE
LOW 0.5 CVE-2025-12940

Credentials recorded in logs in NETGEAR WAX610 and WAX610Y_CVE-2025-12940

Login credentials are inadvertently recorded in logs if a Syslog Server is configured in NETGEAR WAX610 and WAX610Y (AX1800 Dual Band PoE Multi-Gig...

NETGEAR WAX610 CVE
LOW 3.3 CVE-2025-32088

CVE-2025-32088_CVE-2025-32088

Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications may allow a denial of servi...

n/a Intel(R) QAT Windows software before version 2.6.0. CVE
LOW 2 CVE-2025-32037

CVE-2025-32037_CVE-2025-32037

Improper access control for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow a denial of service. Network a...

n/a Intel(R) PresentMon before version 2.3.1 CVE