Recent Advisories

Severity ID Title Vendor Product Date Type
Unknown ADV-9010

DbGate allows for File Traversal via file parameter

CVE Details Basic Information Title DbGate allows for File Traversal via file parameter Type cve Published 2025-07-26T03:27:05.690Z Modified 2025-0...

N/A N/A NEWS
Unknown ADV-9009

HAX CMS Backend Lacks Comprehensive Authorization Checks

CVE Details Basic Information Title HAX CMS Backend Lacks Comprehensive Authorization Checks Type cve Published 2025-07-26T03:27:34.305Z Modified 2...

N/A N/A NEWS
Unknown ADV-9007

XWiki Platform’s searchDocuments API allows for SQL injection

CVE Details Basic Information Title XWiki Platform’s searchDocuments API allows for SQL injection Type cve Published 2025-07-26T03:28:49.269Z...

N/A N/A NEWS
Unknown ADV-9006

skops’ Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution

CVE Details Basic Information Title skops’ Inconsistent Trusted Type Validation Enables Hidden `operator` Methods Execution Type cve Publishe...

N/A N/A NEWS
Unknown ADV-9005

skops’ MethodNode can access unexpected object fields through dot notation, leading to arbitrary code execution at load time

CVE Details Basic Information Title skops’ MethodNode can access unexpected object fields through dot notation, leading to arbitrary code exe...

N/A N/A NEWS
Unknown ADV-9000

DbGate allows Unauthorized File Access via CSV Plugin

CVE Details Basic Information Title DbGate allows Unauthorized File Access via CSV Plugin Type cve Published 2025-07-26T03:34:43.481Z Modified 2025...

N/A N/A NEWS
Unknown ADV-8999

FreeScout’s deserialization of untrusted data leads to Remote Code Execution

CVE Details Basic Information Title FreeScout’s deserialization of untrusted data leads to Remote Code Execution Type cve Published 2025-07-2...

N/A N/A NEWS
Unknown ADV-8996

D-Link DI-8400 jhttpd usb_paswd.asp null pointer dereference

CVE Details Basic Information Title D-Link DI-8400 jhttpd usb_paswd.asp null pointer dereference Type cve Published 2025-07-26T03:02:05.219Z Modifi...

N/A N/A NEWS
Unknown ADV-8990

Linkify 4.3.1 – Prototype Pollution & HTML Attribute Injection (XSS)

CVE Details Basic Information Title Linkify 4.3.1 – Prototype Pollution & HTML Attribute Injection (XSS) Type cve Published 2025-07-25T2...

N/A N/A NEWS
Unknown ADV-8988

D-Link DIR-513 HTTP POST Request formSetWanPPTPpath formSetWanPPTPcallback buffer overflow

CVE Details Basic Information Title D-Link DIR-513 HTTP POST Request formSetWanPPTPpath formSetWanPPTPcallback buffer overflow Type cve Published 2...

N/A N/A NEWS