Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2025-62158

Frappe had attachments made by students to their assignments of type Text set to public_CVE-2025-62158

Frappe Learning is a learning system that helps users structure their content. In versions prior to 2.38.0, the system did stored the attachments u...

frappe lms < 2.38.0 CVE
LOW 2.7 CVE-2025-61921

Sinatra has ReDoS vulnerability in ETag header value generation_CVE-2025-61921

Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability...

sinatra sinatra < 4.2.0 CVE
LOW 3.7 CVE-2025-52635

HCL AION is susceptible to Trusted types in scripts not enforced in CSP_CVE-2025-52635

A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION: 2.0.

HCL AION 2.0 CVE
LOW 3.7 CVE-2025-52625

HCL AION is susceptible to Cacheable SSL Page Found vulnerability_CVE-2025-52625

A vulnerability  Cacheable SSL Page Found vulnerability has been identified in HCL AION.  Cached data may expose credentials, system identifier...

HCL AION 2.0 CVE
LOW 3.7 CVE-2025-52634

HCL AION is susceptible to Spring Boot Actuator Endpoints Exposed_CVE-2025-52634

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION This issue affects HCL AION: 2.0.

HCL HCL AION 2.0 CVE
LOW 3.7 CVE-2025-52630

HCL AION is susceptible to Missing or insecure “X-Content-Type-Options” header vulnerability_CVE-2025-52630

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in HCL AION.This issue affects AION: 2.0.

HCL AION 2.0 CVE
LOW 3.1 CVE-2025-52655

HCL MyXalytics is affected by a Cross-Domain Script Include vulnerability._CVE-2025-52655

Inclusion of Functionality from Untrusted Control Sphere vulnerability in HCL MyXalytics. v6.6 allows Loading third-party scripts without integrity...

HCL HCL MyXalytics 6.6 CVE
LOW 2.4 CVE-2025-21046

CVE-2025-21046_CVE-2025-21046

Improper access control in WindowManager in Samsung DeX prior to SMR Oct-2025 Release 1 allows physical attackers to temporarily access to recent a...

Samsung Mobile Samsung Mobile Devices SMR Oct-2025 Release in Android 13, 14, 15 CVE
LOW 1 CVE-2025-32916

Sensitive form data in URL query parameters_CVE-2025-32916

Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions

Checkmk GmbH Checkmk 2.4.0 CVE
LOW 2 CVE-2025-11489

wonderwhy-er DesktopCommanderMCP filesystem.ts isPathAllowed symlink_CVE-2025-11489

A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects the function isPathAllowed ...

wonderwhy-er DesktopCommanderMCP 0.2.0 CVE