Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2025-58749

WAMR runtime hangs or crashes with large memory.fill addresses in LLVM-JIT mode_CVE-2025-58749

WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. In WAMR versions prior to 2.4.2, when running in LLVM-JIT ...

bytecodealliance wasm-micro-runtime < 2.4.2 CVE
LOW 3.1 CVE-2025-59270

psPAS does not enforce TLS within Get-PASSAMLResponse_CVE-2025-59270

psPAS PowerShell module does not explicitly enforce TLS 1.2 within the 'Get-PASSAMLResponse' function during the SAML authentication process. An un...

pspete psPAS 6.4.85 CVE
LOW 3.3 CVE-2025-43283

CVE-2025-43283_CVE-2025-43283

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Tahoe 26. An app may be able to cause unexpected sy...

Apple macOS unspecified CVE
LOW 2.3 CVE-2025-10316

Cross-Site Scripting in extension “Form to Database” (form_to_database)_CVE-2025-10316

The extension "Form to Database" is susceptible to Cross-Site Scripting. This issue affects the following versions: before 2.2.5, from 3.0.0 before...

TYPO3 Extension "Form to Database" (form_to_database) CVE
LOW 3.5 CVE-2025-26710

CVE-2025-26710_CVE-2025-26710

There is an an information disclosure vulnerability in ZTE T5400. Due to improper configuration of the access control mechanism, attackers can obta...

ZTE T5400 CR_UNIAGT5400V1.0.0B02 CVE
LOW 3.2 CVE-2025-59453

CVE-2025-59453_CVE-2025-59453

Click Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a crafted URL ...

clickstudios Passwordstate CVE
LOW 3.2 CVE-2025-59436

CVE-2025-59436_CVE-2025-59436

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 017700000001 is improperly categorized as globall...

fedorindutny ip CVE
LOW 3.2 CVE-2025-59437

CVE-2025-59437_CVE-2025-59437

The ip (aka node-ip) package through 2.0.1 (in NPM) might allow SSRF because the IP address value 0 is improperly categorized as globally routable ...

fedorindutny ip CVE
LOW 2.1 CVE-2025-43798

CVE-2025-43798_CVE-2025-43798

Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time password (TO...

Liferay DXP 7.3.10 CVE
LOW 3.1 CVE-2025-59399

CVE-2025-59399_CVE-2025-59399

libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error message generation.

EVerest libocpp CVE