Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.7 CVE-2025-8243

TOTOLINK X15 HTTP POST Request formMapDel buffer overflow_CVE-2025-8243

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105 and classified as critical. This issue affects some unknown processing of the file /...

TOTOLINK X15 1.0.0-B20230714.1105 CVE
HIGH 8.7 CVE-2025-8244

TOTOLINK X15 HTTP POST Request formMapDelDevice buffer overflow_CVE-2025-8244

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unknown function of the file /bo...

TOTOLINK X15 1.0.0-B20230714.1105 CVE
HIGH 8.7 CVE-2025-8245

TOTOLINK X15 HTTP POST Request formMultiAPVLAN buffer overflow_CVE-2025-8245

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been declared as critical. Affected by this vulnerability is an unknown func...

TOTOLINK X15 1.0.0-B20230714.1105 CVE
HIGH 8.7 CVE-2025-8246

TOTOLINK X15 HTTP POST Request formRoute buffer overflow_CVE-2025-8246

A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been rated as critical. Affected by this issue is some unknown functionality...

TOTOLINK X15 1.0.0-B20230714.1105 CVE
HIGH 8.2 CVE-2025-8267

CVE-2025-8267_CVE-2025-8267

Versions of the package ssrfcheck before 1.2.0 are vulnerable to Server-Side Request Forgery (SSRF) due to an incomplete denylist of IP address ran...

n/a ssrfcheck CVE
HIGH 8.8 CVE-2025-5997

Privilege Escalation in Beamsec PhishPro_CVE-2025-5997

Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse.This issue affects PhishPro: before 7.5.4.2.

Beamsec PhishPro CVE
HIGH 8.7 CVE-2025-8279

Missing Authentication for Critical Function in GitLab Language Server_CVE-2025-8279

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

GitLab GitLab Language Server 7.6.0 CVE
HIGH 7.2 CVE-2025-2297

Privilege Management for Windows – Elevation of Privilege_CVE-2025-2297

Prior to version 25.4.270.0, a local authenticated attacker can manipulate user profile files to add illegitimate challenge response codes into the...

BeyondTrust Privilege Management for Windows CVE
HIGH 7.7 CVE-2025-54531

CVE-2025-54531_CVE-2025-54531

In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows

JetBrains TeamCity CVE
HIGH 7.5 CVE-2025-54530

CVE-2025-54530_CVE-2025-54530

In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions

JetBrains TeamCity CVE