NA - CVE-2025-54571 - ModSecurity is an open source, cross platform...
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.11 and below, an attacker can override the HTTP response’s...
NA - CVE-2025-54594 - react-native-bottom-tabs is a library of Native...
react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used...
NA - CVE-2025-54801 - Fiber is an Express inspired web framework...
Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data containing a large numeric key that represents a...
NA - CVE-2025-54869 - FPDI is a collection of PHP classes that...
FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. In versions 2.6.2 and below, any application that uses FPDI to...
NA - CVE-2025-54872 - onion-site-template is a complete, scalable tor...
onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor image if the secrets were copied from an existing...
NA - CVE-2025-54873 - RISC Zero is a zero-knowledge verifiable...
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. RISC packages risc0-zkvm versions 2.0.0 through 2.1.0 and...
NA - CVE-2025-54876 - The Janssen Project is an open-source identity...
The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Janssen stores passwords in plaintext in the local cli_cmd.log file. This is fixed...
NA - CVE-2025-54879 - Mastodon is a free, open-source social network...
Mastodon is a free, open-source social network server based on ActivityPub Mastodon which facilitates LDAP configuration for authentication. In versions 3.1.5 through 4.2.24, 4.3.0 through 4.3.11...
NA - CVE-2025-54883 - Vision UI is a collection of enterprise-grade,...
Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the getSecureRandomInt function in security-kit versions prior to 3.5.0...
NA - CVE-2025-54884 - Vision UI is a collection of enterprise-grade,...
Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit...