Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2025-54884

Vision UI security-kit.js: Potential Uncontrolled Resource Allocation Vulnerability_CVE-2025-54884

Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId a...

DavidOsipov Vision-ui < 1.5.0 CVE
HIGH 8.7 CVE-2025-54801

Fiber Susceptible to Crash via `BodyParser` Due to Unvalidated Large Slice Index in Decoder_CVE-2025-54801

Fiber is an Express inspired web framework written in Go. In versions 2.52.8 and below, when using Fiber's Ctx.BodyParser to parse form data contai...

gofiber fiber < 2.52.9 CVE
HIGH 8.7 CVE-2025-54872

onion-site-template tor Secrets Baked Into Image_CVE-2025-54872

onion-site-template is a complete, scalable tor hidden service self-hosting sample. Versions which include commit 3196bd89 contain a baked-in tor i...

Vessel9817 onion-site-template >= 3196bd896fed58306d42cc9f4c1e0760e8c829c9, < bc9ba0fd8cc7fbb3abc6759b351885a4501bce84 CVE
HIGH 8.1 CVE-2025-54655

CVE-2025-54655_CVE-2025-54655

Race condition vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality and in...

Huawei HarmonyOS 5.0.2 CVE
HIGH 8.4 CVE-2025-54653

CVE-2025-54653_CVE-2025-54653

Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentiality of the...

Huawei HarmonyOS 5.0.2 CVE
HIGH 8.4 CVE-2025-54652

CVE-2025-54652_CVE-2025-54652

Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentiality of the...

Huawei HarmonyOS 5.0.2 CVE
HIGH 7.5 CVE-2025-7036

CleverReach WP <= 1.5.20 - Unauthenticated SQL Injection via title Parameter_CVE-2025-7036

The CleverReach® WP plugin for WordPress is vulnerable to time-based SQL Injection via the ‘title’ parameter in all versions up to, and including, ...

cleverreach43 CleverReach® WP * CVE
HIGH 8.3 CVE-2025-54622

CVE-2025-54622_CVE-2025-54622

Binding authentication bypass vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may affect service c...

Huawei HarmonyOS 5.1.0 CVE
HIGH 7.3 CVE-2025-54611

CVE-2025-54611_CVE-2025-54611

EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confiden...

Huawei HarmonyOS 4.3.1 CVE
HIGH 7.7 CVE-2025-54607

CVE-2025-54607_CVE-2025-54607

Authentication management vulnerability in the ArkWeb module. Impact: Successful exploitation of this vulnerability may affect service confidential...

Huawei HarmonyOS 5.1.0 CVE