Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.4 CVE-2025-23291

CVE-2025-23291_CVE-2025-23291

NVIDIA Delegated Licensing Service for all appliance platforms contains a vulnerability where an User/Attacker may cause an authorized action. A su...

NVIDIA DLS component of NVIDIA License System All versions prior to v3.5.1 and v3.1.7 CVE
LOW 3.3 CVE-2025-11195

Rapid7 AppSpider Project Name Validation Bypass_CVE-2025-11195

Rapid7 AppSpider Pro versions below 7.5.021 suffer from a project name validation vulnerability, whereby an attacker can change the project name di...

Rapid7 AppSpider Pro CVE
LOW 3.5 CVE-2025-55795

CVE-2025-55795_CVE-2025-55795

The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email up...

n/a n/a n/a CVE
LOW 2.1 CVE-2025-59163

vet MCP Server SSE Transport DNS Rebinding Vulnerability_CVE-2025-59163

vet is an open source software supply chain security tool. Versions 1.12.4 and below are vulnerable to a DNS rebinding attack due to lack of HTTP H...

safedep vet < 1.12.5 CVE
LOW 3.3 CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes session token in debug output_CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to s...

Medical Informatics Engineering Enterprise Health RC202503 CVE
LOW 3.4 CVE-2025-35032

Medical Informatics Engineering Enterprise Health arbitrary file upload_CVE-2025-35032

Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how ...

Medical Informatics Engineering Enterprise Health CVE
LOW 3.3 CVE-2025-36144

IBM watsonx.data information disclosure_CVE-2025-36144

IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local user.

IBM watsonx.data 2.2 CVE
LOW 2.1 CVE-2025-59842

JupyterLab LaTeX typesetter links did not enforce `noopener` attribute_CVE-2025-59842

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to version 4....

jupyterlab jupyterlab < 4.4.8 CVE
LOW 3.7 CVE-2025-36326

IBM Controller information disclosure_CVE-2025-36326

IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due t...

IBM Cognos Controller 11.0.0 CVE
LOW 3.8 CVE-2025-10871

Missing Authorization in GitLab_CVE-2025-10871

An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1. Project Maint...

GitLab GitLab 16.6 CVE