Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    CVE-2025-56801
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-56800
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-56799
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    JLSEC-2025-183
    Fix available
    Packages

    LibGit2_jll

    Summary

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0

    Published
    21 Oct 2025
    JLSEC-2025-182
    Fix available
    Packages

    LibGit2_jll

    Summary

    An issue was discovered in libgit2 before 0.28.4 and 0.9x before 0.99.0

    Published
    21 Oct 2025
    JLSEC-2025-184
    Fix available
    Packages

    LibGit2_jll

    Summary

    libgit2 is a cross-platform, linkable library implementation of Git

    Published
    21 Oct 2025
    JLSEC-2025-185
    Fix available
    Packages

    LibGit2_jll

    Summary

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a...

    Published
    21 Oct 2025
    JLSEC-2025-186
    Fix available
    Packages

    LibGit2_jll

    Summary

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a...

    Published
    21 Oct 2025
    Packages

    freetype, freetype-demos, freetype-devel

    Summary

    Update of freetype

    Published
    21 Oct 2025
    Packages

    iwl100-firmware, iwl1000-firmware, iwl105-firmware, iwl135-firmware, iwl2000-firmware, iwl2030-firmware, iwl3160-firmware, iwl3945-firmware, iwl4965-firmware, iwl5000-firmware, iwl5150-firmware, iwl6000-firmware, iwl6000g2a-firmware, iwl6000g2b-firmware, iwl6050-firmware, iwl7260-firmware, iwlax2xx-firmware, linux-firmware, linux-nano-firmware

    Summary

    Update of linux-firmware

    Published
    21 Oct 2025
    GHSA-w476-p2h3-79g9
    Fix available
    Packages

    uv

    Summary

    uv has differential in tar extraction with PAX headers

    Published
    21 Oct 2025
    GHSA-9p44-q66p-xm6p
    No fix available
    Packages

    processwire/processwire

    Summary

    ProcessWire CMS vulnerable to resource-exhaustion Denial of Service

    Published
    21 Oct 2025
    GHSA-6pgj-w687-9c8c
    Fix available
    Packages

    com.liferay:com.liferay.portal.cluster.multiple

    Summary

    Liferay Portal fails to verify messages from the cluster network is trusted

    Published
    21 Oct 2025
    CVE-2025-8050
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-60427
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-12031
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    GHSA-8pfh-j44r-f654
    Fix available
    Packages

    github.com/cosmos/evm, github.com/cosmos/evm

    Summary

    Cosmos EVM Vulnerability

    Published
    21 Oct 2025
    GHSA-r2vg-hvjm-fg38
    Fix available
    Packages

    shopware/platform, shopware/platform, shopware/core, shopware/core

    Summary

    Shopware Customer Orders can be canceled, even if refunds are disabled

    Published
    21 Oct 2025
    GHSA-27c9-vp3w-6ww8
    Fix available
    Packages

    shopware/platform, shopware/platform, shopware/core, shopware/core

    Summary

    Shopware exposes sensitive user information via CSV export mapping

    Published
    21 Oct 2025
    GHSA-3cpp-fv95-mpr5
    Fix available
    Packages

    shopware/platform, shopware/platform, shopware/core, shopware/core

    Summary

    Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice

    Published
    21 Oct 2025
    GHSA-6wh5-mw9h-5c3w
    Fix available
    Packages

    shopware/platform, shopware/platform, shopware/core, shopware/core

    Summary

    Shopware vulnerable to path traversal via Plugin upload

    Published
    21 Oct 2025
    GHSA-m895-2hj3-8cg9
    Fix available
    Packages

    shopware/platform, shopware/platform, shopware/core, shopware/core

    Summary

    Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually

    Published
    21 Oct 2025
    JLSEC-2025-181
    Fix available
    Packages

    IntelOpenMP_jll

    Summary

    Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may...

    Published
    21 Oct 2025
    JLSEC-2025-180
    Fix available
    Packages

    JpegTurbo_jll

    Summary

    The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit...

    Published
    21 Oct 2025
    JLSEC-2025-179
    Fix available
    Packages

    JpegTurbo_jll

    Summary

    Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component

    Published
    21 Oct 2025
    JLSEC-2025-178
    Fix available
    Packages

    JpegTurbo_jll

    Summary

    The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based...

    Published
    21 Oct 2025
    JLSEC-2025-177
    Fix available
    Packages

    JpegTurbo_jll

    Summary

    libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the `put_pixel_rows` function in wrbmp.c,...

    Published
    21 Oct 2025
    JLSEC-2025-176
    Fix available
    Packages

    Hwloc_jll

    Summary

    An issue was discovered in open-mpi hwloc 2.1.0 allows attackers to cause a denial of service or...

    Published
    21 Oct 2025
    JLSEC-2025-175
    Fix available
    Packages

    HarfBuzz_ICU_jll, HarfBuzz_jll

    Summary

    hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via...

    Published
    21 Oct 2025
    JLSEC-2025-174
    Fix available
    Packages

    Gettext_jll

    Summary

    An issue was discovered in GNU gettext 0.19.8

    Published
    21 Oct 2025
    Packages

    rust-astral-tokio-tar, rust-astral-tokio-tar

    Summary

    Published
    21 Oct 2025
    CVE-2025-60500
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    UBUNTU-CVE-2025-62518
    No fix available
    Packages

    rust-astral-tokio-tar, rust-astral-tokio-tar

    Summary

    Published
    21 Oct 2025
    CVE-2025-62605
    Fix available
    Packages

    Summary

    Mastodon quotes control can be bypassed

    Published
    21 Oct 2025
    CGA-947q-m6p4-3g23
    Fix available
    Packages

    renovate, renovate

    Summary

    Published
    21 Oct 2025
    CVE-2025-62598
    Fix available
    Packages

    Summary

    WeGIA Vulnerable to Reflected Cross-Site Scripting via Endpoint 'pessoa/editar_info_pessoal.php' Parameter 'action'

    Published
    21 Oct 2025
    CVE-2025-62597
    Fix available
    Packages

    Summary

    WeGIA Vulnerable to Reflected Cross-Site Scripting via Endpoint 'pessoa/editar_info_pessoal.php' Parameter 'sql'

    Published
    21 Oct 2025
    CVE-2025-62595
    Fix available
    Packages

    Summary

    Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic

    Published
    21 Oct 2025
    CVE-2025-62250
    Fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-61194
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-61181
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-60751
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    Packages

    geographiclib, geographiclib, geographiclib

    Summary

    Published
    21 Oct 2025
    CVE-2025-60280
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    CVE-2025-22166
    No fix available
    Packages

    Summary

    Published
    21 Oct 2025
    UBUNTU-CVE-2025-60751
    No fix available
    Packages

    geographiclib, geographiclib, geographiclib, geographiclib, geographiclib, geographiclib, geographiclib

    Summary

    Published
    21 Oct 2025
    CVE-2025-62518
    Fix available
    Packages

    Summary

    astral-tokio-tar Vulnerable to PAX Header Desynchronization

    Published
    21 Oct 2025
    GHSA-j5gw-2vrg-8fgx
    Fix available
    Packages

    astral-tokio-tar, tokio-tar

    Summary

    astral-tokio-tar Vulnerable to PAX Header Desynchronization

    Published
    21 Oct 2025
    Packages

    mbedtls, mbedtls, mbedtls

    Summary

    Published
    21 Oct 2025
    Packages

    mbedtls, mbedtls, mbedtls, mbedtls, mbedtls

    Summary

    Published
    21 Oct 2025