Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.4 8554EEFB-671E-

Exploit for CVE-2025-8088_8554EEFB-671E-5F42-84A6-FDFF5ACCCC93

WinRAR-CVE-2025-8088-PoC-RAR WinRAR 0day CVE-2025-8088 PoC RAR Archive Place the My_Resume_final.rar in the Downloads Directory and extract using &...

N/A N/A GITHUBEXPLOIT
HIGH 7.5 3565DE25-F143-

Exploit for CVE-2025-50154_3565DE25-F143-5AAE-AAAF-1F5481FBD631

NTLM/SMB Hardening & Threat Hunt Toolkit Author: w01f Version: 1.0 Purpose: Audit, harden, and hunt for insecure NTLM/SMB usage to mitigate ris...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 CVE-2025-6184

Tutor LMS Pro – eLearning and online course solution <= 3.7.0 - Authenticated (Tutor Instructor+) SQL Injection_CVE-2025-6184

The Tutor LMS Pro – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter u...

themeum Tutor LMS Pro * CVE
HIGH 8.7 CVE-2025-8761

INSTAR 2K+/4K Backend IPC Server denial of service_CVE-2025-8761

A vulnerability has been found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This vulnerability affects unknown code of the component Backend IPC Server....

INSTAR 2K+ 3.11.1 Build 1124 CVE
HIGH 7 CVE-2025-8762

INSTAR 2K+/4K UART improper physical access control_CVE-2025-8762

A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The m...

INSTAR 2K+ 3.11.1 Build 1124 CVE
HIGH 8.1 FB62377C-C33E-

Exploit for CVE-2025-50286_FB62377C-C33E-57D3-B7D0-80694827D8CF

Grav CMS v1.7.48 / Admin Plugin v1.10.48 - Authenticated RCE via Plugin Upload (CVE-2025-50286)...

N/A N/A GITHUBEXPLOIT
HIGH 7.8 CVE-2025-41686

Improper File Permissions Allow Local Privilege Escalation_CVE-2025-41686

A low-privileged local attacker can exploit improper permissions on nssm.exe to escalate their privileges and gain administrative access.

Phoenix Contact DaUM 0.0.0 CVE
HIGH 7.8 CVE-2025-30033

CVE-2025-30033_CVE-2025-30033

The affected setup component is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code when a legitimate user installs...

Siemens Automation License Manager V6.0 CVE
HIGH 8.3 CVE-2025-40743

CVE-2025-40743_CVE-2025-40743

A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINUMERIK ...

Siemens SINUMERIK 828D PPU.4 CVE
HIGH 7.8 CVE-2025-40759

CVE-2025-40759_CVE-2025-40759

A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions), SIMATIC STEP 7 V18 (All versions), ...

Siemens SIMATIC S7-PLCSIM V17 CVE