Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.3 CVE-2025-8751

Protected Total WebShield Extension Block Page cross site scripting_CVE-2025-8751

A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has been classified as problematic. This affects an unkn...

Protected Total WebShield Extension 3.0 CVE
LOW 3.7 CVE-2025-54999

OpenBao: Timing Side-Channel in Userpass Auth Method_CVE-2025-54999

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In version...

openbao openbao >= 0.1.0, < 2.3.2 CVE
LOW 2.7 CVE-2025-55188

CVE-2025-55188_CVE-2025-55188

7-Zip before 25.01 does not always properly handle symbolic links during extraction.

7-Zip 7-Zip CVE
LOW 2.3 CVE-2025-8708

Antabot White-Jotter com.gm.wj.config.ShiroConfiguration ShiroConfiguration.java CookieRememberMeManager deserialization_CVE-2025-8708

A vulnerability was found in Antabot White-Jotter 0.22. It has been declared as critical. This vulnerability affects the function CookieRememberMeM...

Antabot White-Jotter 0.22 CVE
LOW 3.5 CVE-2025-38746

CVE-2025-38746_CVE-2025-38746

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A...

Dell SupportAssist OS Recovery N/A CVE
LOW 3.7 CVE-2025-54787

SuiteCRM: Improper Authorization for attachment downloads_CVE-2025-54787

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. There is a vulnerability in SuiteCRM vers...

SuiteCRM SuiteCRM >= 7.14.6, < 7.14.7 CVE
LOW 2.3 CVE-2025-54799

Lego does not enforce HTTPS_CVE-2025-54799

Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the...

go-acme lego < 4.25.2 CVE
LOW 2.5 CVE-2025-54798

tmp does not restrict arbitrary temporary file / directory write via symbolic link `dir` parameter_CVE-2025-54798

tmp is a temporary file and directory creator for node.js. In versions 0.2.3 and below, tmp is vulnerable to an arbitrary temporary file / director...

raszi node-tmp < 0.2.4 CVE
LOW 3.3 CVE-2025-21022

CVE-2025-21022_CVE-2025-21022

Improper access control in Galaxy Wearable prior to version 2.2.63.25042861 allows local attackers to access sensitive information.

Samsung Mobile Galaxy Wearable 2.2.63.25042861 CVE
LOW 3.3 CVE-2025-21023

CVE-2025-21023_CVE-2025-21023

Improper access control in WcsExtension for Galaxy Watch prior to Android Watch 16 allows local attackers to access sensitive information.

Samsung Mobile WcsExtension for Galaxy Watch Android Watch 16 CVE