Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.6 CVE-2025-55383

CVE-2025-55383_CVE-2025-55383

Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files of any extension to any loc...

n/a n/a n/a CVE
HIGH 8.8 MALWAREBYTES:70...

All Apple users should update after company patches zero-day vulnerability in all platforms_MALWAREBYTES:706BCD0DE2FB27440170B7A638B7B2F0

Apple has released security updates for iPhones, iPads and Macs to fix a zero-day vulnerability (a vulnerability which Apple was previously unaware...

N/A N/A MALWAREBYTES
HIGH 8.1 CVE-2025-27215

CVE-2025-27215_CVE-2025-27215

An Improper Access Control could allow a malicious actor authenticated in the API of certain UniFi Connect Display Cast devices to make unsupported...

Ubiquiti Inc UniFi Connect Display Cast 1.10.7 CVE
HIGH 8.8 CVE-2025-27216

CVE-2025-27216_CVE-2025-27216

Multiple Incorrect Permission Assignment for Critical Resource in UISP Application may allow a malicious actor with certain permissions to escalate...

Ubiquiti Inc UISP Application 2.4.220 CVE
HIGH 8.8 CVE-2025-55368

CVE-2025-55368_CVE-2025-55368

Incorrect access control in the component \controller\RoleController.java of jshERP v3.5 allows unauthorized attackers to arbitrarily modify the su...

n/a n/a n/a CVE
HIGH 8.8 CVE-2025-55370

CVE-2025-55370_CVE-2025-55370

Incorrect access control in the component \controller\ResourceController.java of jshERP v3.5 allows unauthorized attackers to obtain all the corres...

n/a n/a n/a CVE
HIGH 8.1 CVE-2025-9185

CVE-2025-9185_CVE-2025-9185

Memory safety bugs present in Firefox ESR 115.26, Firefox ESR 128.13, Thunderbird ESR 128.13, Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141...

Mozilla Firefox unspecified CVE
HIGH 8.1 CVE-2025-9184

CVE-2025-9184_CVE-2025-9184

Memory safety bugs present in Firefox ESR 140.1, Thunderbird ESR 140.1, Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memo...

Mozilla Firefox unspecified CVE
HIGH 8.8 CVE-2025-50902

CVE-2025-50902_CVE-2025-50902

Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to ...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-48978

CVE-2025-48978_CVE-2025-48978

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to...

Ubiquiti Inc EdgeMAX EdgeSwitch 1.11.1 CVE