Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.2 CVE-2025-59447

CVE-2025-59447_CVE-2025-59447

The YoSmart YoLink Smart Hub device 0382 exposes a UART debug interface. An attacker with direct physical access can leverage this interface to rea...

YoSmart YoLink Smart Hub 0382 CVE
LOW 3.5 CVE-2025-59451

CVE-2025-59451_CVE-2025-59451

The YoSmart YoLink application through 2025-10-02 has session tokens with unexpectedly long lifetimes.

YoSmart YoLink application CVE
LOW 3.6 CVE-2025-61984

CVE-2025-61984_CVE-2025-61984

ssh in OpenSSH before 10.1 allows control characters in usernames that originate from certain possibly untrusted sources, potentially leading to co...

OpenBSD OpenSSH CVE
LOW 3.6 CVE-2025-61985

CVE-2025-61985_CVE-2025-61985

ssh in OpenSSH before 10.1 allows the '\0' character in an ssh:// URI, potentially leading to code execution when a ProxyCommand is used.

OpenBSD OpenSSH CVE
LOW 2.1 CVE-2025-61769

Emlog vulnerable to stored XSS in file upload functionality in emlog_CVE-2025-61769

Emlog is an open source website building system. A cross-site scripting (XSS) vulnerability in emlog up to and including version 2.5.22 allows auth...

emlog emlog <= 2.5.22 CVE
LOW 3.8 CVE-2025-58578

Unlimited user creation by authorized users_CVE-2025-58578

A user with the appropriate authorization can create any number of user accounts via an API endpoint using a POST request. There are no qu...

SICK AG Enterprise Analytics all versions CVE
LOW 2.7 CVE-2025-58589

Information Disclosure Through Stacktrace_CVE-2025-58589

When an error occurs in the application a full stacktrace is provided to the user. The stacktrace lists class and method names as well as other int...

SICK AG Baggage Analytics all versions CVE
LOW 2.3 CVE-2025-11281

Frappe LMS Unpublished Course courses access control_CVE-2025-11281

A vulnerability has been found in Frappe LMS 2.35.0. The affected element is an unknown function of the file /courses/ of the component Unpublished...

Frappe LMS 2.35.0 CVE
LOW 2.5 CVE-2025-61677

DataChain: Deserialization of Untrusted Data from Environment Variables_CVE-2025-61677

DataChain is a Python-based AI-data warehouse for transforming and analyzing unstructured data. Versions 0.34.1 and below allow for deseriaization ...

iterative datachain < 0.34.2 CVE
LOW 2.3 CVE-2025-59829

Claude Code: Permission deny bypass is possible through symlink_CVE-2025-59829

Claude Code is an agentic coding tool. Versions below 1.0.120 failed to account for symlinks when checking permission deny rules. If a user explici...

anthropics claude-code < 1.0.120 CVE