Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-10014

elunez eladmin Email Address updateEmail updateUserEmail improper authorization_CVE-2025-10014

A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component E...

elunez eladmin 2.0 CVE
LOW 3.3 CVE-2025-0076

CVE-2025-0076_CVE-2025-0076

In multiple locations, there is a possible way to view icons belonging to another user due to a missing permission check. This could lead to local ...

Google Android 15 CVE
LOW 2.7 CVE-2025-58866

WordPress Site Info Plugin <= 1.1 - Sensitive Data Exposure Vulnerability_CVE-2025-58866

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Rami Yushuvaev Site Info allows Retrieve Embedded Sensi...

Rami Yushuvaev Site Info n/a CVE
LOW 2.1 CVE-2025-58352

Weblate has long session expiry times during second factor verification_CVE-2025-58352

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second fac...

WeblateOrg weblate < 5.13.1 CVE
LOW 3.2 CVE-2025-26428

CVE-2025-26428_CVE-2025-26428

In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physic...

Google Android 15 CVE
LOW 2.7 CVE-2025-2667

IBM Sterling B2B Integrator information disclosure_CVE-2025-2667

IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1 and 6.2.0.0 through 6.2.0.4 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1 and 6.2.0...

IBM Sterling B2B Integrator 6.0.0.0 CVE
LOW 2.3 CVE-2025-58064

CKEditor is susceptible to Cross-Site Scripting (XSS) through its clipboard package_CVE-2025-58064

CKEditor 5 is a modern JavaScript rich-text editor with an MVC architecture. ckeditor5 and ckeditor5-clipboard versions 46.0.0 through 46.0.2 and 4...

ckeditor ckeditor5 >= 46.0.0, < 46.0.3 CVE
LOW 3.8 CVE-2025-57146

CVE-2025-57146_CVE-2025-57146

phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobileno parameter.

n/a n/a n/a CVE
LOW 2.1 CVE-2025-41000

Cross-Frame Scripting (XFS) in BoomCMS_CVE-2025-41000

Cross-Frame Scripting (XFS) vulnerability in BoomCMS v9.1.4 from UXB London. XFS is a web attack technique that exploits specific browser bugs to s...

BoomCMS BoomCMS 9.1.4 CVE
LOW 2.7 CVE-2025-9821

SSRF via webhook function_CVE-2025-9821

SummaryUsers with webhook permissions can conduct SSRF via webhooks. If they have permission to view the webhook logs, the (partial) request respon...

Mautic Mautic >= 4.4.0 CVE