Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-54336

CVE-2025-54336_CVE-2025-54336

In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string, then an...

n/a n/a n/a CVE
CRITICAL 10 CVE-2025-50567

CVE-2025-50567_CVE-2025-50567

Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the deprecated /e ...

n/a n/a n/a CVE
CRITICAL 10 THN:143E65C4342...

Public Exploit for Chained SAP Flaws Exposes Unpatched Systems to Remote Code Execution_THN:143E65C4342D6D8160EF9CA683D2C98D

![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=) A new exploit combining tw...

N/A N/A THN
CRITICAL 9.9 056E4D1E-04E9-

Exploit for CVE-2025-49113_056E4D1E-04E9-596C-B560-7BDF74005A0A

CVE-2025-49113-Roundcube-RCE-PHP...........................

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 FC9EA752-0404-

Exploit for CVE-2025-8723_FC9EA752-0404-53AA-9BBE-29CFB2C1D14B

⚡️ Cloudflare Image Resizing Description: The plugin's REST...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2025-6758

Real Spaces – WordPress Properties Directory Theme <= 3.6 - Unauthenticated Privilege Escalation to Administrator via 'imic_agent_register'_CVE-2025-6758

The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' func...

imithemes Real Spaces - WordPress Properties Directory Theme * CVE
CRITICAL 9.8 CVE-2025-8723

Cloudflare Image Resizing <= 1.5.6 - Missing Authentication to Unauthenticated Remote Code Execution via rest_pre_dispatch Hook_CVE-2025-8723

The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient sanitizati...

mecanik Cloudflare Image Resizing – Optimize & Accelerate Your Images * CVE
CRITICAL 9.1 CVE-2025-54156

Santesoft Sante PACS Server Cleartext Transmission of Sensitive Information_CVE-2025-54156

The Sante PACS Server Web Portal sends credential information without encryption.

Santesoft Sante PACS Server CVE
CRITICAL 9.8 65FAD546-0AA8-

Exploit for CVE-2025-6934_65FAD546-0AA8-531B-9227-B4AAD843EB1B

# CVE-2025-6934 – WordPress Opal Estate Pro Exploit 📖 Description This repository contains a **Proof of Concept (PoC) exploit** for **CVE-20...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 9023DF99-28AF-

Exploit for Code Injection in Apache Rocketmq_9023DF99-28AF-5E08-A4DF-3ACF072B2F90

## Apache RocketMQ [![Build Status](https://travis-ci.org/apache/rocketmq.svg?branch=master)](https://travis-ci.org/apache/rocketmq) [![Coverage S...

N/A N/A GITHUBEXPLOIT