5.3
CVE-2025-54879 - Mastodon eโmail throttle misconfiguration allows unlimited email confirmations against unconfirmed โฆ
Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11 and 4.4.0 through 4.4.3, Mastodon's rate-limiting system has a critical configuration error where the eโฆ
6.9
CVE-2025-54571 - ModSecurity's Insufficient Return Value Handling can Lead to XSS and Source Code Disclosure
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP responseโs Content-Type, which could lead to several issues depending on the HTTP scenario. For example, we have demonstrateโฆ
8.7
CVE-2025-54884 - Vision UI security-kit.js: Potential Uncontrolled Resource Allocation Vulnerability
Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit versions prior to 3.5.0 (packaged in Vision UI 1.4.0 and below) are vulnerable to Denial of Service (DoSโฆ
9.3
CVE-2025-54883 - Vision UI's security-kit Contains Cryptographic Weakness
Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the getSecureRandomInt function in security-kit versions prior to 3.5.0 (packaged in Vision-ui <= 1.4.0) contains a critical cryptographic weakness. Due to a silent 32-bit inโฆ
6.9
CVE-2025-54876 - Jans CLI stores plaintext passwords in the local cli_cmd.log file
The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed in the nightly prerelease.
2.7
CVE-2025-54873 - RISC Zero Underconstrained Vulnerability: Division
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and risc0-circuit-rv32im and risc0-circuit-rv32im-sys versions 2.0.0 through 2.0.4 contain vulnerabilities where signed inteโฆ
6
CVE-2025-54869 - FPDI is Vulnerable to Memory Exhaustion (OOM) through its PDF Parser
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. In versions 2.6.2 and below, any application that uses FPDI to process user-supplied PDF files is at risk, causing a Denial of Service (DoS) vulnerability. An attacker โฆ
8.7
CVE-2025-54801 - Fiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a slice index (e.g., test.18446744073704), the application crashes due to an out-of-bounds slice allocation in โฆ
9.1
CVE-2025-54594 - react-native-bottom-tabs: Arbitrary code execution in GitHub Actions canary workflow leads to secreโฆ
react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, which allowed for untrusted code from a forked pull request toโฆ
8.7
CVE-2025-54125 - XWiki Platform: Password and email exposure in xml.vm fields
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform Legacy Old Core and XWiki Platform Old Core versions 1.1 through 16.4.6, 16.5.0-rc-1 through 16.10.4 and 17.0.0-rc-1 through 17.1.0, the XML export of a page in XWiki that can be โฆ