Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2025-5042

RFA File Parsing Out-of-Bounds Read Vulnerability_CVE-2025-5042

A maliciously crafted RFA file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage t...

Autodesk Revit 2026 CVE
HIGH 8.8 CVE-2025-51482

CVE-2025-51482_CVE-2025-51482

Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute ar...

n/a n/a n/a CVE
HIGH 7.7 CVE-2025-6741

CVE-2025-6741_CVE-2025-6741

Improper access control in secure message component in Devolutions Server allows an authenticated user to steal unauthorized entries via the secure...

Devolutions Server CVE
HIGH 7.7 CVE-2025-6523

CVE-2025-6523_CVE-2025-6523

Use of weak credentials in emergency authentication component in Devolutions Server allows an unauthenticated attacker to bypass authentication via...

Devolutions Server CVE
HIGH 8.8 CVE-2025-51464

CVE-2025-51464_CVE-2025-51464

Cross-site Scripting (XSS) in aimhubio Aim 3.28.0 allows remote attackers to execute arbitrary JavaScript in victims browsers via malicious Python ...

n/a n/a n/a CVE
HIGH 7.3 CVE-2025-31512

CVE-2025-31512_CVE-2025-31512

An issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval via isAddedByApprover in a Request%20Building%20A...

n/a n/a n/a CVE
HIGH 8.7 CVE-2025-7724

Unauthenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2_CVE-2025-7724

An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V...

TP-Link Systems Inc. VIGI NVR1104H-4P V1 CVE
HIGH 8.5 CVE-2025-7723

Authenticated command injection on VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2_CVE-2025-7723

A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue aff...

TP-Link Systems Inc. VIGI NVR1104H-4P V1 CVE
HIGH 8.8 CVE-2025-8040

CVE-2025-8040_CVE-2025-8040

Memory safety bugs present in Firefox ESR 140.0, Thunderbird ESR 140.0, Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memo...

Mozilla Firefox unspecified CVE
HIGH 8.1 CVE-2025-8039

CVE-2025-8039_CVE-2025-8039

In some cases search terms persisted in the URL bar even after navigating away from the search page. This vulnerability affects Firefox < 141, Fire...

Mozilla Firefox unspecified CVE