Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.1 CVE-2025-59398

CVE-2025-59398_CVE-2025-59398

The OCPP implementation in libocpp before 0.26.2 allows a denial of service (EVerest crash) via JSON input larger than 255 characters, because a Ci...

EVerest libocpp CVE
LOW 2.3 CVE-2025-43792

CVE-2025-43792_CVE-2025-43792

Remote staging in Liferay Portal 7.4.0 through 7.4.3.105, and older unsupported versions, and Liferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7...

Liferay Portal 7.4.0 CVE
LOW 3.7 CVE-2025-59376

CVE-2025-59376_CVE-2025-59376

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-delete, e.g...

feiskyer mcp-kubernetes-server CVE
LOW 3.7 CVE-2025-59377

CVE-2025-59377_CVE-2025-59377

feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl because shell=True is used. NOT...

feiskyer mcp-kubernetes-server CVE
LOW 3.1 CVE-2025-9084

Open redirect in OAuth login_CVE-2025-9084

Mattermost versions 10.5.x

Mattermost Mattermost 10.5.0 CVE
LOW 2.3 CVE-2025-0164

IBM QRadar SIEM information disclosure_CVE-2025-0164

IBM QRadar SIEM 7.5 through 7.5 Update Pack 13 Independent Fix 01 could allow a local privileged user to perform unauthorized actions on configurat...

IBM QRadar SIEM 7.5 CVE
LOW 2 AF9B92A2-4E8A-

Exploit for CVE-2025-3639_AF9B92A2-4E8A-5594-BCB3-3E35DEA6B9CF

CVE-2025-3639 PoC - Liferay Portal/DXP Login Bypass This repository contains...

N/A N/A GITHUBEXPLOIT
LOW 3.5 CVE-2025-3650

jQuery Colorbox <= 4.6.3 - Contributor+ Stored XSS_CVE-2025-3650

The jQuery Colorbox WordPress plugin through 4.6.3 uses the colorbox library, which does not sanitize title attributes on links before using them, ...

Unknown jQuery Colorbox CVE
LOW 2.3 CVE-2025-10320

iteachyou Dreamer CMS updatePwd weak password_CVE-2025-10320

A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. ...

iteachyou Dreamer CMS 4.1.3.0 CVE
LOW 2.4 CVE-2025-4234

Cortex XDR Microsoft 365 Defender Pack: Cleartext Exposure of Credentials_CVE-2025-4234

A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normal...

Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack 4.6.0 CVE