Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2025-6207

WP Import Export Lite <= 3.9.28 - Authenticated (Subscriber+) Arbitrary File Upload_CVE-2025-6207

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_tempalte_im...

vjinfotech WP Import Export Lite * CVE
HIGH 7.5 CVE-2025-5061

WP Import Export Lite <= 3.9.29 - Authenticated (Subscriber+) Arbitrary File Upload_CVE-2025-5061

The WP Import Export Lite plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpie_parse_uploa...

vjinfotech WP Import Export Lite * CVE
HIGH 7.8 CVE-2025-41698

Draeger: ICMHelper is vulnerable to a privilege escalation due too missing authorization_CVE-2025-41698

A low privileged local attacker can interact with the affected service although user-interaction should not be allowed.

Draeger Draeger ICMHelper CVE
HIGH 8.4 CVE-2025-7032

Rockwell Automation Stack-based Buffer Overflow In Arena® Simulation_CVE-2025-7032

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end o...

Rockwell Automation Arena® Simulation 16.20.09 and prior CVE
HIGH 8.4 CVE-2025-7025

Rockwell Automation Heap-based Buffer Overflow In Arena® Simulation_CVE-2025-7025

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end o...

Rockwell Automation Arena® Simulation 16.20.09 and prior CVE
HIGH 7.5 CVE-2025-29745

CVE-2025-29745_CVE-2025-29745

A vulnerability affecting the scanning module in Emsisoft Anti-Malware prior to 2024.12 allows attackers on a remote server to obtain Net-NTLMv2 ha...

n/a n/a n/a CVE
HIGH 7.4 CVE-2025-43979

CVE-2025-43979_CVE-2025-43979

An issue was discovered on FIRSTNUM JC21A-04 devices through 2.01ME/FN that allows authenticated attackers to execute arbitrary OS system commands ...

n/a n/a n/a CVE
HIGH 7.1 CVE-2025-7674

navify Monitoring API input validation_CVE-2025-7674

Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a den...

Roche Diagnostics navify Monitoring CVE
HIGH 8.6 CVE-2025-54254

Adobe Experience Manager | Improper Restriction of XML External Entity Reference (‘XXE’) (CWE-611)_CVE-2025-54254

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability...

Adobe Adobe Experience Manager CVE
HIGH 7.4 CVE-2025-43978

CVE-2025-43978_CVE-2025-43978

Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?f...

n/a n/a n/a CVE