Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2025-44652

CVE-2025-44652_CVE-2025-44652

In Netgear RAX30 V1.0.10.94_3, the USERLIMIT_GLOBAL option is set to 0 in multiple bftpd-related configuration files. This can cause DoS attacks wh...

n/a n/a n/a CVE
HIGH 8.6 CVE-2025-36845

CVE-2025-36845_CVE-2025-36845

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The endpoint /_internal/redirect.php allows for Server-Side Request Forgery (SSRF). Th...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-51869

CVE-2025-51869_CVE-2025-51869

Insecure Direct Object Reference (IDOR) vulnerability in Liner thru 2025-06-03 allows attackers to gain sensitive information via crafted space_id,...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-51868

CVE-2025-51868_CVE-2025-51868

Insecure Direct Object Reference (IDOR) vulnerability in Dippy (chat.dippy.ai) v2 allows attackers to gain sensitive information via the conversati...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-53832

@translated/lara-mcp vulnerable to command injection in import_tmx tool_CVE-2025-53832

Lara Translate MCP Server is a Model Context Protocol (MCP) Server for Lara Translate API. Versions 0.0.11 and below contain a command injection vu...

translated lara-mcp < 0.0.12 CVE
HIGH 7.6 CVE-2025-53528

Cadwyn is vulnerable to an XSS attack through its docs page_CVE-2025-53528

Cadwyn creates production-ready community-driven modern Stripe-like API versioning in FastAPI. In versions before 5.4.3, the version parameter of t...

zmievsa cadwyn < 5.4.3 CVE
HIGH 7.2 CVE-2025-54128

HAX CMS NodeJs’s Disabled Content Security Policy Enables Cross-Site Scripting_CVE-2025-54128

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.7 and below, the NodeJS version of HAX CMS h...

haxtheweb issues < 11.0.8 CVE
HIGH 7.1 CVE-2025-54134

HAX CMS NodeJs’s Improper Error Handling Leads to Denial of Service_CVE-2025-54134

HAX CMS NodeJs allows users to manage their microsite universe with a NodeJs backend. In versions 11.0.8 and below, the HAX CMS NodeJS application ...

haxtheweb issues < 11.0.9 CVE
HIGH 8.7 CVE-2025-7945

D-Link DIR-513 formSetWanDhcpplus buffer overflow_CVE-2025-7945

A vulnerability was found in D-Link DIR-513 up to 20190831. It has been declared as critical. This vulnerability affects the function formSetWanDhc...

D-Link DIR-513 20190831 CVE
HIGH 8.1 CVE-2025-6585

WP JobHunt <= 7.2 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Account Deletion_CVE-2025-6585

The WP JobHunt plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 7.2 via the cs_remove_p...

n/a WP JobHunt * CVE