Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2025-59345

Dragonfly did not enable authentication for some Manager’s endpoints_CVE-2025-59345

Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs and /preheats endpoints in ...

dragonflyoss dragonfly < 2.1.0 CVE
LOW 1.2 CVE-2025-58767

REXML has a DoS condition when parsing malformed XML file_CVE-2025-58767

REXML is an XML toolkit for Ruby. The REXML gems from 3.3.3 to 3.4.1 has a DoS vulnerability when parsing XML containing multiple XML declarations....

ruby rexml >= 3.3.3, < 3.4.2 CVE
LOW 2.6 D84B4564-FBAF-

Exploit for CVE-2024-45712_D84B4564-FBAF-53C3-8249-DA0DB9F7C851

WooCommerce Vulnerability Scanner (CVE-2024-45712) A Python script designed to scan a...

N/A N/A GITHUBEXPLOIT
LOW 2.7 CVE-2025-59161

In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left_CVE-2025-59161

Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient vali...

element-hq element-web < 1.11.112 CVE
LOW 3.3 CVE-2025-43301

CVE-2025-43301_CVE-2025-43301

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, m...

Apple macOS unspecified CVE
LOW 2.8 CVE-2025-43349

CVE-2025-43349_CVE-2025-43349

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 26, macOS Sonoma 14.8, macOS Sequoia 15.7, i...

Apple macOS unspecified CVE
LOW 3.3 CVE-2025-43344

CVE-2025-43344_CVE-2025-43344

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in tvOS 26, watchOS 26, visionOS 26, macOS Tahoe 26,...

Apple iOS and iPadOS unspecified CVE
LOW 3.1 CVE-2025-59270

psPAS does not enforce TLS 1.2 within Get-PASSAMLResponse_CVE-2025-59270

psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML authentication process. An un...

pspete psPAS 6.4.85 CVE
LOW 2.7 CVE-2025-59160

matrix-js-sdk has insufficient validation when considering a room to be upgraded by another_CVE-2025-59160

Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room ...

matrix-org matrix-js-sdk < 38.2.0 CVE
LOW 2.2 CVE-2025-30075

CVE-2025-30075_CVE-2025-30075

In Alludo MindManager before 25.0.208 on Windows, attackers could potentially execute code as other local users on the same machine if they could w...

Alludo MindManager CVE