Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2025-58272

CVE-2025-58272_CVE-2025-58272

Cross-site request forgery vulnerability exists in Web Caster V130 versions 1.08 and earlier. If a logged-in user views a malicious page created by...

NTT EAST, Inc. Web Caster V130 1.08 and earlier CVE
LOW 3.7 CVE-2025-7039

Glib: buffer under-read on glib through glib/gfileutils.c via get_tmp_file()_CVE-2025-7039

A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to poten...

Red Hat Red Hat Enterprise Linux 10 CVE
LOW 2.3 CVE-2025-8662

CVE-2025-8662_CVE-2025-8662

OpenAM (OpenAM Consortium Edition) contains a vulnerability that may cause it to malfunction as a SAML IdP due to a tampered request.This issue aff...

OpenAM consortium OpenAM 14.0.0 CVE
LOW 1.8 CVE-2025-9806

Tenda F1202 Administrative shadow hard-coded credentials_CVE-2025-9806

A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown function of the file /etc_ro/shadow of the componen...

Tenda F1202 1.2.0.9 CVE
LOW 1.3 CVE-2025-58161

MobSF Path Traversal in GET /download/ using absolute filenames_CVE-2025-58161

MobSF is a mobile application security testing tool used. In version 4.4.0, the GET /download/ route uses string path verification via os.path.comm...

MobSF Mobile-Security-Framework-MobSF = 4.4.0 CVE
LOW 2.3 CVE-2025-9799

Langfuse Webhook promptRouter.ts promptChangeEventSourcing server-side request forgery_CVE-2025-9799

A security flaw has been discovered in Langfuse up to 3.88.0. Affected by this vulnerability is the function promptChangeEventSourcing of the file ...

n/a Langfuse 3.0 CVE
LOW 3.5 CVE-2025-55007

Knowage vulnerable to server-side request forgery_CVE-2025-55007

Knowage is an open source analytics and business intelligence suite. Prior to version 8.1.37, Knowage is vulnerable to server-side request forgery....

KnowageLabs Knowage-Server < 8.1.37 CVE
LOW 1.8 CVE-2025-9778

Tenda W12 Administrative shadow hard-coded credentials_CVE-2025-9778

A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an unknown function of the file /etc_ro/shadow of the comp...

Tenda W12 1.0.0.1(5411) CVE
LOW 2.4 CVE-2025-9769

D-Link DI-7400G+ mng_platform.asp sub_478D28 command injection_CVE-2025-9769

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng_platform.asp. The manipula...

D-Link DI-7400G+ 19.12.25A1 CVE
LOW 2 CVE-2025-9731

Tenda AC9 Administrative shadow hard-coded credentials_CVE-2025-9731

A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown function of the file /etc_ro/shadow of the component Ad...

Tenda AC9 15.03.05.19 CVE