3.1
CVE-2025-62379 - Open Redirect in reflex-dev/reflex
Reflex is a library to build full-stack web apps in pure Python. In versions 0.5.4 through 0.8.14, the /auth-codespace endpoint automatically assigns the redirect_to query parameter value directly to client-side links without any validation and triggers automatic clicks when the page loads in a Gitโฆ
5.5
CVE-2025-59419 - Netty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email Forgery
Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.128.Final and 4.2.7.Final, the SMTP codec in Netty contains an SMTP command injection vulnerability due to insufficient input validation for Carriage Return (\r) and Line Feed (\n) characters in user-suppโฆ
7.5
CVE-2025-62370 - Alloy Core has a DoS vulnerability on `alloy_dyn_abi::TypedData` hashing
Alloy Core libraries at the root of the Rust Ethereum ecosystem. Prior to 0.8.26 and 1.4.1, an uncaught panic triggered by malformed input to alloy_dyn_abi::TypedData could lead to a denial-of-service (DoS) via eip712_signing_hash(). Software with high availability requirements such as network servโฆ
2.9
CVE-2025-2529 - IBM Terracotta denial of service
Applications using affected versions of Ehcache 3.x can experience degraded cache-write performance if the application using Ehcache utilizes keys sourced from (malicious) external parties in an unfiltered/unsalted way.
8.7
CVE-2025-61990 - TMM vulnerability
When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.5
CVE-2025-57780 - F5OS Vulnerability
A vulnerability exists in F5OS-A and F5OS-C system that may allow an authenticated attacker with local access to escalate their privileges.ย A successful exploit may allow the attacker to cross a security boundary.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not โฆ
5.1
CVE-2025-61933 - BIG-IP APM cross-site scripting (XSS) vulnerability
A reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of BIG-IP APM that allows an attacker to run JavaScript in the context of the targeted logged-out user.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.7
CVE-2025-58071 - BIG-IP IPSec vulnerability
When IPsec is configured on the BIG-IP system, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.7
CVE-2025-61935 - BIG-IP Advanced WAF and ASM vulnerability
When a BIG IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
5.6
CVE-2025-53860 - F5OS-A FIPS HSM vulnerability
A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems.ย ย Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.