Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2025-51986

CVE-2025-51986_CVE-2025-51986

An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to reach an infinite loop via ...

n/a n/a n/a CVE
HIGH 8.1 CVE-2025-8342

WooCommerce OTP Login With Phone Number, OTP Verification <= 1.8.47 - Authentication Bypass_CVE-2025-8342

The WooCommerce OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass due to insufficient empty...

glboy WooCommerce OTP Login With Phone Number, OTP Verification * CVE
HIGH 7.5 CVE-2025-6025

Order Tip for WooCommerce <= 1.5.4 - Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts_CVE-2025-6025

The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including,...

railmedia Order Tip for WooCommerce * CVE
HIGH 8.7 CVE-2025-9006

Tenda CH22 delFileName formdelFileName buffer overflow_CVE-2025-9006

A vulnerability was identified in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function formdelFileName of the file /goform/delFileNam...

Tenda CH22 1.0.0.1 CVE
HIGH 7.3 CVE-2025-9000

Mechrevo Control Center GX V2 reg File uncontrolled search path_CVE-2025-9000

A vulnerability was found in Mechrevo Control Center GX V2 5.56.51.48. Affected by this vulnerability is an unknown functionality of the component ...

Mechrevo Control Center GX V2 5.56.51.48 CVE
HIGH 7.5 CVE-2025-8979

Tenda AC15 Firmware Update check_fw data authenticity_CVE-2025-8979

A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/split_fireware/check_fw of t...

Tenda AC15 15.13.07.13 CVE
HIGH 7.5 CVE-2025-8980

Tenda G1 Firmware Update check_upload_file data authenticity_CVE-2025-8980

A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of the component Firmware Upda...

Tenda G1 16.01.7.8(3660) CVE
HIGH 7.1 CVE-2025-52765

WordPress NetInsight Analytics Implementation Plugin <= 1.0.3 - Cross Site Request Forgery (CSRF) Vulnerability_CVE-2025-52765

Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin allows Stored XSS. This issue affects NetIns...

lisensee NetInsight Analytics Implementation Plugin n/a CVE
HIGH 8.2 CVE-2025-52797

WordPress StoryMap Plugin <= 2.1 - Cross Site Request Forgery (CSRF) Vulnerability_CVE-2025-52797

Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap allows SQL Injection. This issue affects StoryMap: from n/a through 2.1.

josepsitjar StoryMap n/a CVE
HIGH 7.1 CVE-2025-53575

WordPress Primer MyData for Woocommerce Plugin <= 4.2.5 - Cross Site Request Forgery (CSRF) Vulnerability_CVE-2025-53575

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in primersoftware Primer MyData for Woocommerce ...

primersoftware Primer MyData for Woocommerce n/a CVE