Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.8 CVE-2025-50902

CVE-2025-50902_CVE-2025-50902

Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to ...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-48978

CVE-2025-48978_CVE-2025-48978

An Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.11.0 and earlier) could allow a Command Injection by a malicious actor with access to...

Ubiquiti Inc EdgeMAX EdgeSwitch 1.11.1 CVE
HIGH 8.8 CVE-2025-43300

CVE-2025-43300_CVE-2025-43300

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sonoma 14.7.8, macOS Ventura 13.7.8, iPadOS ...

Apple macOS unspecified CVE
HIGH 8.7 CVE-2025-9303

TOTOLINK A720R cstecgi.cgi setParentalRules buffer overflow_CVE-2025-9303

A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParentalRules of the file /cgi-bin/...

TOTOLINK A720R 4.1.5cu.630_B20250509 CVE
HIGH 7.3 C6D16AC3-BCFF-

Exploit for CVE-2025-22235_C6D16AC3-BCFF-5D26-A8BF-AF2537610D59

CVE-2025-22235:......

N/A N/A GITHUBEXPLOIT
HIGH 8.8 007C40A6-C735-

Exploit for Path Traversal in Rarlab Winrar_007C40A6-C735-59E8-B7C5-CB0A01F3A0BD

CVE-2025-8088 WinRAR: WinRAR path traversal allowing arbitrary code execution (CVE-2025-8088) CVE-2025-8088...

N/A N/A GITHUBEXPLOIT
HIGH 8.7 CVE-2025-9299

Tenda M3 getMasterPassengerAnalyseData formGetMasterPassengerAnalyseData stack-based overflow_CVE-2025-9299

A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPassengerAnalyseData of the file /...

Tenda M3 1.0.0.12 CVE
HIGH 8.7 CVE-2025-9298

Tenda M3 QuickIndex formQuickIndex stack-based overflow_CVE-2025-9298

A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the a...

Tenda M3 1.0.0.12 CVE
HIGH 8.6 CVE-2025-28041

CVE-2025-28041_CVE-2025-28041

Incorrect access control in the doFilter function of itranswarp up to 2.19 allows attackers to access sensitive components without authentication.

n/a n/a n/a CVE
HIGH 8.7 CVE-2025-9297

Tenda i22 wxportalauth formWeixinAuthInfoGet stack-based overflow_CVE-2025-9297

A vulnerability was detected in Tenda i22 1.0.0.3(4687). This impacts the function formWeixinAuthInfoGet of the file /goform/wxportalauth. Performi...

Tenda i22 1.0.0.3(4687) CVE