StackRadar

CVE-2025-11731

Low

Advisory

Published 14 Oct 2025In the index since 5 Sept 2026
Severity
Low
worst across findings
CVSS
3.1
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
600
of 17,787 indexed, latest versions
Container images
379
deployed by those charts
Fix available
None
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 600 of 17,787 indexed charts deploy, on 379 images.

Affected packageAffected versionsFixed inImages
libxsltdeb1.1.28-2.1ubuntu0.3, 1.1.28-2ubuntu0.1, 1.1.29-5ubuntu0.2, 1.1.34-4+17 moreno fix listed379
OSV records
DEBIAN-CVE-2025-11731UBUNTU-CVE-2025-11731

Charts affected

600 by stars
ChartLatestAffected imagesRadar Score
nominatimnominatim-chart1.3.01 of 3See more

nominatim nominatim-chart 1.3.0

1 of the 3 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
mediagis/nominatim:3.7c15e941485ef
libxslt@1.1.34-4ubuntu0.20.04.1
no fix listed

Open the chart page →

22,713
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

5,887
keycloak-helm-chartnotesprojectchart0.1.01 of 2See more

keycloak-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,638
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

6,864
notes-admin-front-helm-chartnotesprojectchart0.1.01 of 1See more

notes-admin-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
vlebediantsev/notes-admin-front:latest007c6670ff48
libxslt@1.1.35-1
no fix listed

Open the chart page →

13,331
notes-project-fromt-helm-chartnotesprojectchart0.1.01 of 1See more

notes-project-fromt-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
vlebediantsev/notes-project-front:latest945675fd2636
libxslt@1.1.35-1
no fix listed

Open the chart page →

13,405
registration-ms-front-helm-chartnotesprojectchart0.1.01 of 1See more

registration-ms-front-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-front-app-host:latest54f69d116c50
libxslt@1.1.35-1
no fix listed

Open the chart page →

13,387
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

5,928
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

5,885
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libxslt@1.1.29-5ubuntu0.2
no fix listed

Open the chart page →

27,667
firecrawlobeoneVerified publisher3.0.31 of 5See more

firecrawl obeone 3.0.3

1 of the 5 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
ghcr.io/firecrawl/nuq-postgres:latestf9388bd25ae2
libxslt@1.1.35-1.2+deb13u2
no fix listed

Open the chart page →

9,895
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:134689940c6838
libxslt@1.1.35-1.2+deb13u2
no fix listed

Open the chart page →

17,085
web-chartoje-ktcloudlab0.1.01 of 1See more

web-chart oje-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
paperless-ngxoli-the-devVerified publisher1.1.11 of 1See more

paperless-ngx oli-the-dev 1.1.1

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

4,644
ontoserverontoserverVerified publisher0.5.21 of 2See more

ontoserver ontoserver 0.5.2

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:16f1c3376c26f2
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,638
onyx-stackonyx0.3.11 of 12See more

onyx-stack onyx 0.3.1

1 of the 12 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
onyxdotapp/onyx-backend:latest473fdffe4e67
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

6,252
commonground-gatewayopencatalogi1.5.31 of 7See more

commonground-gateway opencatalogi 1.5.3

1 of the 7 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/gateway-ui:stag6a5594b7b32c
libxslt@1.1.35-1
no fix listed

Open the chart page →

9,736
opentickopenchartVerified publisher0.1.01 of 1See more

opentick openchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:1.25.5a484819eb602
libxslt@1.1.35-1
no fix listed

Open the chart page →

5,688
opencost-parquet-exporteropencostVerified publisher0.3.11 of 1See more

opencost-parquet-exporter opencost 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
ghcr.io/opencost/opencost-parquet-exporter:v0.2.1ce85ef0ce665
libxslt@1.1.35-1
no fix listed

Open the chart page →

11,003
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

7,848
sohaopensohaVerified publisher0.1.91 of 2See more

soha opensoha 0.1.9

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
pgvector/pgvector:0.8.5-pg18-trixie9d2e61c7352b
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,770
hiveopstty0.1.91 of 4See more

hive opstty 0.1.9

1 of the 4 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16233f361c5819
libxslt@1.1.35-1
no fix listed

Open the chart page →

4,539
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
yetiplatform/yeti-frontend:2.9.0873ef15d267b
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

72,154
yetiosdfir-infrastructureVerified publisher1.0.51 of 4See more

yeti osdfir-infrastructure 1.0.5

1 of the 4 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
yetiplatform/yeti-frontend:latest709064278c7e
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

6,544
webot-container-kit0.1.01 of 1See more

web ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
workerot-container-kit0.1.01 of 1See more

worker ot-container-kit 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
lens-metric-proxyowan-charts0.1.01 of 1See more

lens-metric-proxy owan-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
radiusp2p-avs0.1.01 of 1See more

radius p2p-avs 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
theradius/loggia:0.463ba348546ec
libxslt@1.1.35-1
no fix listed

Open the chart page →

11,095
ungatep2p-avs0.1.02 of 3See more

ungate p2p-avs 0.1.0

2 of the 3 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
xom4ekp2p/infini-route-attestators-public-mainnet-attester:latestd0e0aa238b02
libxslt@1.1.35-1
no fix listed
xom4ekp2p/infini-route-attestators-public-mainnet-avs-webapi:latest2745b5fd8785
libxslt@1.1.35-1
no fix listed

Open the chart page →

25,681
examplepauls-helm-charts0.1.21 of 1See more

example pauls-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
kubeconpauls-helm-charts0.1.01 of 1See more

kubecon pauls-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
matomopetbattle11.0.11 of 2See more

matomo petbattle 11.0.1

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
bitnamilegacy/matomo:5.3.2-debian-12-r13f02c000c54b1
libxslt@1.1.35-1+deb12u2
no fix listed

Open the chart page →

10,801
phronetisphronetis0.1.271 of 2See more

phronetis phronetis 0.1.27

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
knspar/phronetis-operator:0.1.60c4f0543ee58
libxslt@1.1.35-1
no fix listed

Open the chart page →

15,077
seafilephybros-helm-charts4.0.11 of 1See more

seafile phybros-helm-charts 4.0.1

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
seafileltd/seafile-mc:9.0.97ac833196f60
libxslt@1.1.34-4ubuntu0.20.04.1
no fix listed

Open the chart page →

22,146
subgraph-oraclepinaxVerified publisher0.0.11 of 1See more

subgraph-oracle pinax 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
ghcr.io/graphprotocol/availability-oracle:sha-28312fd472a25038957
libxslt@1.1.35-1
no fix listed

Open the chart page →

11,373
pingdom-operatorpingdom-operator0.0.201 of 1See more

pingdom-operator pingdom-operator 0.0.20

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
ghcr.io/nefelim4ag/pingdom-operator:0.0.15f8c7afdcf439
libxslt@1.1.35-1
no fix listed

Open the chart page →

11,017
web-chartpjw-ktcloudlab0.1.01 of 1See more

web-chart pjw-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
planectlplanectlVerified publisher0.7.02 of 10See more

planectl planectl 0.7.0

2 of the 10 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:17.6.0-debian-12-r4926356130b77
libxslt@1.1.35-1+deb12u2
no fix listed
library/node:208f693eaa7e0a
libxslt@1.1.35-1+deb12u3
no fix listed

Open the chart page →

25,626
plex-media-serverplex-media-server1.9.01 of 1See more

plex-media-server plex-media-server 1.9.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
plexinc/pms-docker:1.43.3.10896-cb3ebc72d83a425ae9e13
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed

Open the chart page →

970
k8s-oidc-discovery-providerpnnl-miscscripts0.1.21 of 2See more

k8s-oidc-discovery-provider pnnl-miscscripts 0.1.2

1 of the 2 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:1.29.49dd288848f44
libxslt@1.1.35-1.2+deb13u2
no fix listed

Open the chart page →

4,273
nginx-apppnnl-miscscripts0.1.21 of 1See more

nginx-app pnnl-miscscripts 0.1.2

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
pixiecore-simpleconfigpnnl-miscscripts0.1.51 of 1See more

pixiecore-simpleconfig pnnl-miscscripts 0.1.5

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:stabled5792f71a949
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839
pod-birdspod-birds0.1.01 of 1See more

pod-birds pod-birds 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
teknas09/bird-pod:latest12a1fa85c4aa
libxslt@1.1.35-1
no fix listed

Open the chart page →

11,680
podnat-state-storepodnat-controller0.3.21 of 1See more

podnat-state-store podnat-controller 0.3.2

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
dgraziotin/nginx-webdav-nononsense:1.23.138f2de42bed0
libxslt@1.1.34-4
no fix listed

Open the chart page →

9,212
libretimepodzone-chartsVerified publisher0.4.13 of 9See more

libretime podzone-charts 0.4.1

3 of the 9 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed
library/postgres:16.24aea012537ed
libxslt@1.1.35-1
no fix listed
ghcr.io/libretime/icecast:latest3c98b92e9535
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

11,181
agentpolyaxon2.16.43 of 4See more

agent polyaxon 2.16.4

3 of the 4 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
libxslt@1.1.35-1.2+deb13u3
no fix listed
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
libxslt@1.1.35-1.2+deb13u3
no fix listed
polyaxon/polyaxon-streams:2.16.4c186bd9834c0
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

10,004
polyaxonpolyaxon2.16.44 of 5See more

polyaxon polyaxon 2.16.4

4 of the 5 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
bitnamilegacy/postgresql:16.4.0-debian-12-r1102e2f47a405e
libxslt@1.1.35-1
no fix listed
polyaxon/polyaxon-agent:2.16.4eca6952b20e6
libxslt@1.1.35-1.2+deb13u3
no fix listed
polyaxon/polyaxon-api:2.16.42b55c3265a90
libxslt@1.1.35-1.2+deb13u3
no fix listed
polyaxon/polyaxon-cli:2.16.4024ff3fa775e
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

13,520
postgrespostgresVerified publisher0.1.11 of 1See more

postgres postgres 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:13.12ced3ba927f4c
libxslt@1.1.35-1
no fix listed

Open the chart page →

4,363
svc-postgrespostgres-fiap-lanches0.1.01 of 1See more

svc-postgres postgres-fiap-lanches 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/postgres:latest4ef4dbc939d6
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,638
web-chartpsb-ktcloudlab0.1.01 of 1See more

web-chart psb-ktcloudlab 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-11731.

Container imageDigestPackageFixed in
library/nginx:latest05b8cb60c354
libxslt@1.1.35-1.2+deb13u3
no fix listed

Open the chart page →

1,839

Container images carrying it

379 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/openunison/openunison-k8s-react:1.0.2afb3e9282952
libxslt@1.1.34-4ubuntu0.22.04.4
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.13.10642357c5dbd
libxslt@1.1.35-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.134b05bcd28e69
libxslt@1.1.35-1.2+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.357ad9565bff3
libxslt@1.1.35-1.2+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.5665f2f5cc548
libxslt@1.1.35-1.2+deb13u2
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.0.1ab255bea133e
libxslt@1.1.35-1
no fix listed
1
ghcr.io/paperless-ngx/paperless-ngx:2.20.14b89f83345532
libxslt@1.1.35-1.2+deb13u2
no fix listed
1
ghcr.io/qubiva/qubiva:v0.3.2cdf1e3329bfe
libxslt@1.1.35-1.2+deb13u3
no fix listed
1
ghcr.io/rss-bridge/rss-bridge:latest606896116558
libxslt@1.1.35-1+deb12u4
no fix listed
1
ghcr.io/sdwbgn/unitycatalog-helm/docker/unitycatalog-ui:0.2.1-5d668c1ed07e7ca098d
libxslt@1.1.35-1
no fix listed
1
ghcr.io/sergelogvinov/pgbouncer:16.1518f1121ba0a4
libxslt@1.1.35-1+deb12u4
no fix listed
1
ghcr.io/sergelogvinov/postgresql:16.15fafb72e98f22
libxslt@1.1.35-1+deb12u4
no fix listed
1
ghcr.io/stirling-tools/stirling-pdf:2.14.33b3670fce70b
libxslt@1.1.39-0exp1ubuntu0.24.04.3
no fix listed
1
ghcr.io/substra/substra-frontend:1.0.0e230e6ac0722
libxslt@1.1.35-1
no fix listed
1
ghcr.io/wgbh-mla/pbcore-util:pr-66e04659a3baa
libxslt@1.1.35-1+deb12u3
no fix listed
1
ghcr.io/wittdennis/calibre-web:1.1.1aa7d5d5dd6be
libxslt@1.1.35-1+deb12u4
no fix listed
1
ghcr.io/wizarrrr/wizarr:4.2.0-beta.3d19d886d5090
libxslt@1.1.35-1
no fix listed
1
ghcr.io/zoriya/kyoo_autosync:4.7.1fbba58ddb1a6
libxslt@1.1.35-1
no fix listed
1
ghcr.io/zoriya/kyoo_scanner:4.7.17dc0ee57b628
libxslt@1.1.35-1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service:v1.16.17b1493760c716
libxslt@1.1.35-1
no fix listed
1
public.ecr.aws/jtekt-corporation/image-storage-service-gui:v1.9.434823c8abe00
libxslt@1.1.35-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager:v2.8.15cd62142d6ed
libxslt@1.1.35-1
no fix listed
1
public.ecr.aws/jtekt-corporation/shinsei-manager-front:v1.5.5f8fb4eea4071
libxslt@1.1.35-1
no fix listed
1
public.ecr.aws/jtekt-corporation/time-series-storage-service:v1.5.1046ef5c9ed50
libxslt@1.1.35-1
no fix listed
1
public.ecr.aws/supportpal/helpdesk-monolithic:4.0.4573779e57fae
libxslt@1.1.34-4
no fix listed
1
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
libxslt@1.1.35-1
no fix listed
1
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
libxslt@1.1.35-1
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-frontend:1.0.3166353ce9bf98
libxslt@1.1.35-1.2+deb13u2
no fix listed
1
registry.gitlab.com/enbuild-staging/vivsoft-platform-ui/enbuild-mq-consumer:1.0.310e3cd8c7776d
libxslt@1.1.35-1+deb12u4
no fix listed
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.