Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 3.8 CVE-2025-22873

Improper access to parent directory of root in os_CVE-2025-22873

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would ...

Go standard library os CVE
LOW 2.4 CVE-2026-1966

YugabyteDB Anywhere Exposes LDAP Credentials in Cleartext in Web UI_CVE-2026-1966

YugabyteDB Anywhere displays LDAP bind passwords configured via gflags in cleartext within the web UI. An authenticated user with access to the con...

YugabyteDB Inc YugabyteDB Anywhere 2025.1.0.0 CVE
LOW 3.5 CVE-2025-2134

IBM Jazz Reporting Service Denial of Service_CVE-2025-2134

IBM Jazz Reporting Service could allow an authenticated user on the network to affect the system's performance using complicated queries due to ins...

IBM Jazz Reporting Service 7.1 CVE
LOW 3.5 CVE-2025-27550

IBM Jazz Reporting Service Information Disclosure_CVE-2025-27550

IBM Jazz Reporting Service could allow an authenticated user on the host network to obtain sensitive information about other projects that reside o...

IBM Jazz Reporting Service 7.1 CVE
LOW 3.5 CVE-2025-1823

IBM Jazz Reporting Service Denial of Service_CVE-2025-1823

IBM Jazz Reporting Service could allow an authenticated user on the host network to cause a denial of service using specially crafted SQL query tha...

IBM Jazz Reporting Service 7.1 CVE
LOW 2.3 CVE-2026-1892

WeKan REST API boards.js setBoardOrgs improper authorization_CVE-2026-1892

A security vulnerability has been detected in WeKan up to 8.20. This affects the function setBoardOrgs of the file models/boards.js of the componen...

n/a WeKan 8.0 CVE
LOW 3.1 CVE-2026-20732

BIG-IP Configuration utility vulnerability_CVE-2026-20732

A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages.  Note: Software vers...

F5 BIG-IP 21.0.0 CVE
LOW 3.3 CVE-2026-20730

BIG-IP Edge Client for Windows vulnerability_CVE-2026-20730

A vulnerability exists in BIG-IP Edge Client and browser VPN clients on Windows that may allow attackers to gain access to sensitive information.  ...

F5 BIG-IP Edge Client 7.2.5 CVE
LOW 2.7 CVE-2026-1791

Arbitrary File Upload Vulnerability in Operation and Maintenance Security Gateway_CVE-2026-1791

Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Uplo...

Hillstone Networks Operation and Maintenance Security Gateway V5.5ST00001B113 CVE
LOW 3.1 CVE-2026-24513

ingress-nginx auth-url protection bypass_CVE-2026-24513

A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the pre...

Kubernetes ingress-nginx CVE