Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.5 CVE-2025-47890

CVE-2025-47890_CVE-2025-47890

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] in FortiOS 7.6.0 through 7.6.2, 7.4.0 through 7.4.8, 7.2 all versions, 7.0 all versi...

Fortinet FortiOS 7.6.0 CVE
LOW 3.8 CVE-2025-8594

Pz-LinkCard < 2.5.7 - Contributor+ SSRF_CVE-2025-8594

The Pz-LinkCard WordPress plugin before 2.5.7 does not validate a parameter before making a request to it, which could allow users with a role as l...

Unknown Pz-LinkCard CVE
LOW 3.5 CVE-2025-40773

CVE-2025-40773_CVE-2025-40773

A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulne...

Siemens SiPass integrated CVE
LOW 3.1 CVE-2025-11731

Libxslt: type confusion in exsltfuncresultcompfunction of libxslt_CVE-2025-11731

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT elements during stylesheet parsing. Due to improper type ha...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 3 CVE-2025-42909

Security Misconfiguration vulnerability in SAP Cloud Appliance Library Appliances_CVE-2025-42909

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existi...

SAP_SE SAP Cloud Appliance Library Appliances TITANIUM_WEBAPP 4.0 CVE
LOW 3.5 CVE-2025-62178

WeGIA Cross-Site Scripting (XSS) Reflected endpoint ‘/html/atendido/cadastro_atendido_parentesco_pessoa_nova.php’ parameter ‘idatendido’_CVE-2025-62178

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a Reflected Cross-Site Scripting (X...

LabRedesCefetRJ WeGIA < 3.5.1 CVE
LOW 3.5 CVE-2025-62174

Mastodon allows continued access after password reset via CLI_CVE-2025-62174

Mastodon is a free, open-source social network server based on ActivityPub. In Mastodon before 4.4.6, 4.3.14, and 4.2.27, when an administrator re...

mastodon mastodon >= 4.4.0-beta.1, < 4.4.6 CVE
LOW 3.5 CVE-2025-58084

Mattermost Desktop App crashes when clicking on malformed external URL_CVE-2025-58084

Mattermost Desktop App versions

Mattermost Mattermost CVE
LOW 2.4 CVE-2025-27259

Ericsson Network Manager: improper neutralization of user controlled input_CVE-2025-27259

Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited, can exfiltrate limited data or redirect victims ...

Ericsson Ericsson Network Manager(ENM) CVE
LOW 3.5 CVE-2025-31995

HCL Unica MaxAI Workbench is vulnerable to improper input validation_CVE-2025-31995

HCL Unica MaxAI Workbench is vulnerable to improper input validation. This allows attackers to exploit vulnerabilities such as SQL Injection, XSS,...

HCL Software MaxAI Workbench v12.1.10 - v25.1 CVE