Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.1 CVE-2025-27238

API hostprototype.get lists data to users with insufficient authorization._CVE-2025-27238

Due to a bug in Zabbix API, the hostprototype.get method lists all host prototypes to users that do not have any user groups assigned to them.

Zabbix Zabbix 7.0.0 CVE
LOW 2.3 CVE-2025-10287

roncoo roncoo-pay orderQuery direct request_CVE-2025-10287

A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element is an unknown function of ...

roncoo roncoo-pay 9428382af21cd5568319eae7429b7e1d0332ff40 CVE
LOW 1 CVE-2025-43789

CVE-2025-43789_CVE-2025-43789

JSON Web Services in Liferay Portal 7.4.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.9, 7.4 GA through update 92 published to OSG...

Liferay Portal 7.4.0 CVE
LOW 2.7 CVE-2025-59047

matrix-sdk-base has panic in the `RoomMember::normalized_power_level()` method_CVE-2025-59047

matrix-sdk-base is the base component to build a Matrix client library. In matrix-sdk-base before 0.14.1, calling the `RoomMember::normalized_power...

matrix-org matrix-rust-sdk < 0.14.1 CVE
LOW 2.3 CVE-2025-10252

SEAT Queue Ticket Kiosk Java RMI Registry deserialization_CVE-2025-10252

A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This mani...

SEAT Queue Ticket Kiosk 20250827 CVE
LOW 2.3 CVE-2025-10250

DJI Mavic Spark/Mavic Air/Mavic Mini Telemetry Channel hard-coded key_CVE-2025-10250

A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function of the component Telemetry ...

DJI Mavic Spark 01.00.0500 CVE
LOW 2.1 CVE-2025-10216

GrandNode Voucher ConfirmOrder race condition_CVE-2025-10216

A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the compo...

n/a GrandNode 2.0 CVE
LOW 3.3 CVE-2025-10222

Sensitive Information Disclosure in Diagnostic Dumps in AxxonSoft Axxon One VMS_CVE-2025-10222

Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) in the diagnostic dump component in AxxonSoft Axxon One VMS 2.0.0 through 2.0....

AxxonSoft AxxonOne 2.0.0 CVE
LOW 3.1 CVE-2025-8277

Libssh: memory exhaustion via repeated key exchange in libssh_CVE-2025-8277

A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to fr...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 3.1 CVE-2025-40802

CVE-2025-40802_CVE-2025-40802

A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaus...

Siemens RUGGEDCOM RST2428P CVE