Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.4 CVE-2025-55100

Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()_CVE-2025-55100

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio1...

Eclipse Foundation USBX CVE
LOW 2.1 CVE-2025-11896

Stack overflow in Xpdf 4.05 due to object loop in PDF CMap_CVE-2025-11896

In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the "UseCMap" entry, leads to infinite recursion and a stack overflow.

Xpdf Xpdf CVE
LOW 3.8 CVE-2025-61924

PrestaShop Checkout Target PayPal merchant account hijacking from backoffice_CVE-2025-61924

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal m...

PrestaShopCorp ps_checkout < 4.4.1 CVE
LOW 3.8 CVE-2025-62412

LibreNMS alert-rules Cross-Site Scripting Vulnerability_CVE-2025-62412

LibreNMS is a community-based GPL-licensed network monitoring system. The alert rule name in the Alerts > Alert Rules page is not properly sanitiz...

librenms librenms < 25.10.0 CVE
LOW 3.1 CVE-2025-54499

Insecure string comparison enables timing attacks_CVE-2025-54499

Mattermost versions 10.5.x

Mattermost Mattermost 10.5.0 CVE
LOW 3.1 CVE-2025-10545

Guest user can add unauthorized team users to private channels_CVE-2025-10545

Mattermost versions 10.5.x

Mattermost Mattermost 10.5.0 CVE
LOW 2.2 CVE-2025-56746

CVE-2025-56746_CVE-2025-56746

Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful authentication, enabling session fixation attacks...

n/a n/a n/a CVE
LOW 3.1 CVE-2025-62379

Open Redirect in reflex-dev/reflex_CVE-2025-62379

Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace endpoint automatically assig...

reflex-dev reflex >= 0.5.4, < 0.8.15 CVE
LOW 2.9 CVE-2025-62380

Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails_CVE-2025-62380

mailgen is a Node.js package that generates responsive HTML e-mails for sending transactional mail. Mailgen versions through 2.0.31 contain an HTML...

eladnava mailgen < 2.0.32 CVE
LOW 2.9 CVE-2025-2529

IBM Terracotta denial of service_CVE-2025-2529

Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys ...

IBM Terracotta 10.15.0 CVE