Vulnerability disclosure
Sonar security: We find, we fix.
Our commitment to code security extends beyond your application. Sonar’s dedicated security research team continuously identifies and responsibly discloses vulnerabilities across key open source projects and packages.

Featured disclosed vulnerabilities
| Severity | Software | Impact | Links |
|---|---|---|---|
4.1 CVE-2025-53637 | meshtastic/firmware
| Repository Takeover
| |
9.3 CVE-2025-61584 | serverless-dns
| Repository Takeover
| |
6.5 CVE-2025-32779 | EDDI
| Remote Code Execution
| |
7.8 CVE-2025-25251 | FortiClient
| Privilege Escalation
| |
5.3 CVE-2025-22859 | Fortinet EMS
| Session Takeover
| |
10 CVE-2024-1597 | PgJDBC
| SQL Injection
| |
6.8 CVE-2025-2703 | Grafana
| Session Takeover
| |
10 CVE-2024-29201 | JumpServer
| Remote Code Execution
| |
8.3 CVE-2024-35219 | OpenAPI Generator
| File Read
| |
9.3 CVE-2024-42009 | Roundcube
| Session Takeover
| |
9.9 CVE-2024-39930 | Gogs
| Remote Code Execution
| |
6.2 CVE-2024-30270 | Mailcow
| Remote Code Execution
|