Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 CVE-2025-51726

CVE-2025-51726_CVE-2025-51726

CyberGhostVPNSetup.exe (Windows installer) is signed using the weak cryptographic hash algorithm SHA-1, which is vulnerable to collision attacks. T...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-27211

CVE-2025-27211_CVE-2025-27211

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with access to...

Ubiquiti Inc EdgeMAX EdgeSwitch 1.11.0 CVE
HIGH 8.7 CVE-2025-54870

VTun-ng’s failure to initialize encryption modules may cause reversion to plaintext_CVE-2025-54870

VTun-ng is a Virtual Tunnel over TCP/IP network. In versions 3.0.17 and below, failure to initialize encryption modules might cause reversion to pl...

leakingmemory vtun-ng >= 3.0.12, < 3.0.18 CVE
HIGH 7.3 CVE-2025-54865

Tilesheets MediaWiki Extension is Vulnerable to Potential SQL Injection_CVE-2025-54865

Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missing backtick in a query execu...

FTB-Gamepedia Tilesheets <= 5.0.3 CVE
HIGH 7.9 CVE-2025-54803

js-toml is vulnerable to Prototype Pollution_CVE-2025-54803

js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. In versions below 1.0.2, a prototype pollution vulnerability in ...

sunnyadn js-toml < 1.0.2 CVE
HIGH 8.7 CVE-2025-54795

Claude Code echo command allowed bypass of user approval prompt for command execution_CVE-2025-54795

Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass the Claude Code confirmati...

anthropics claude-code < 1.0.20 CVE
HIGH 7.7 CVE-2025-54794

Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access_CVE-2025-54794

Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead of canonical path comparison...

anthropics claude-code < 0.2.111 CVE
HIGH 7.7 CVE-2025-54780

glpi-screenshot-plugin exposes local files in /ajax/screenshot.php_CVE-2025-54780

The glpi-screenshot-plugin allows users to take screenshots or screens recording directly from GLPI. In versions below 2.0.2, authenticated user ca...

cconard96 glpi-screenshot-plugin < 2.0.2 CVE
HIGH 8.6 CVE-2025-54135

Cursor Agent is vulnerable to prompt injection via MCP Special Files_CVE-2025-54135

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If t...

cursor cursor < 1.3.9 CVE
HIGH 7.5 CVE-2025-54130

Cursor Agent is vulnerable prompt injection via Editor Special Files_CVE-2025-54130

Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions less than 1.3.9. ...

cursor cursor < 1.3.9 CVE