Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.3 CVE-2025-8393

Dreame Technology iOS and Android Mobile Applications Improper Certificate Validation_CVE-2025-8393

A TLS vulnerability exists in the phone application used to manage a connected device. The phone application accepts self-signed certificates when ...

Dreame Technology Dreamehome iOS app CVE
HIGH 8.8 CVE-2025-53520

EG4 Electronics EG4 Inverters Download of Code Without Integrity Check_CVE-2025-53520

The affected product allows firmware updates to be downloaded from EG4's website, transferred via USB dongles, or installed through EG4's Monitor...

EG4 Electronics EG4 12kPV all versions CVE
HIGH 7.5 CVE-2025-8355

XXE leading to SSRF_CVE-2025-8355

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML con...

Xerox FreeFlow Core CVE
HIGH 7.1 CVE-2025-36119

IBM i authentication bypass_CVE-2025-36119

IBM i 7.3, 7.4, 7.5, and 7.6 is affected by an authenticated user obtaining elevated privileges with IBM Digital Certificate Manager for i (DCM) du...

IBM i 7.3 CVE
HIGH 8.4 CVE-2025-8088

Path traversal vulnerability in WinRAR_CVE-2025-8088

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive...

win.rar GmbH WinRAR CVE
HIGH 8.8 CVE-2025-8748

OS command injection in MiR robots and MiR fleet via crafted HTTP requests_CVE-2025-8748

MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP request crafted by an authenticat...

Mobile Industrial Robots MiR Robots CVE
HIGH 7.8 CVE-2025-38747

CVE-2025-38747_CVE-2025-38747

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local a...

Dell SupportAssist OS Recovery N/A CVE
HIGH 8.4 CVE-2025-54886

skops: Card.get_model does not block arbitrary code execution_CVE-2025-54886

skops is a Python library which helps users share and ship their scikit-learn based models. In versions 0.12.0 and below, the Card.get_model does n...

skops-dev skops < 0.13.0 CVE
HIGH 8.3 CVE-2025-6633

RBG File Parsing Out-of-Bounds Write Vulnerability_CVE-2025-6633

A maliciously crafted RBG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverag...

Autodesk 3ds Max 2026 CVE
HIGH 7.8 CVE-2025-6634

TGA File Parsing Memory Corruption Vulnerability_CVE-2025-6634

A maliciously crafted TGA file, when linked or imported into Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can l...

Autodesk 3ds Max 2026 CVE