Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 D1522323-B251-

Exploit for CVE-2025-54253_D1522323-B251-5226-B2A3-59C86FCBD94E

CVE-2025-54253 Adobe AEM OGNL Injection Simulated PoC Lab Table of contents - Overview - What this repository contains - Goals - Threat model - S...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 473D5F33-8E0F-

Exploit for Path Traversal in Redhat Keycloak_473D5F33-8E0F-59CD-BA58-8F320A6DA42E

Keycloak Keycloak is an Open Source Identity and Access Management solution for modern Applications and Services. This repository contains the sour...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 6B223B9E-1BCC-

Exploit for Improper Privilege Management in Najeebmedia Simple_User_Registration_6B223B9E-1BCC-5F2C-AA56-7E6507045974

CVE-2025-4334 - Simple User Registration --form ``` Arguments: -u / --url → Base WordPress URL (e.g. https://target.com/wordpress/) --form → Full...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 5B52B1EC-F6BA-

Exploit for CVE-2025-49132_5B52B1EC-F6BA-5508-970F-5FC58BCD3A03

CVE-2025-49132 PoC (Improved) This is an improved version of the CVE-2025-49132 proof of concept exploit. CVE Information CVE ID: CVE-2025-49132 N...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2025-55591

CVE-2025-55591_CVE-2025-55591

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endp...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-55293

Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB_CVE-2025-55293

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite ...

meshtastic firmware < 2.6.3 CVE
CRITICAL 9.3 CVE-2025-7693

Rockwell Automation Micro800 Vulnerability_CVE-2025-7693

A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED...

Rockwell Automation PLC - Micro850 L50E V20.011 - V22.011 CVE
CRITICAL 9.4 CVE-2025-55299

VaulTLS has a password-based login exploit in additional user accounts_CVE-2025-55299

VaulTLS is a modern solution for managing mTLS (mutual TLS) certificates. Prior to 0.9.1, user accounts created through the User web UI have an emp...

7ritn VaulTLS < 0.9.1 CVE
CRITICAL 9.1 CVE-2025-55283

aiven-db-migrate allows Privilege Escalation through use of psql during migration_CVE-2025-55283

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows elevation to superu...

aiven aiven-db-migrate < 1.0.7 CVE
CRITICAL 9.1 CVE-2025-55282

aiven-db-migrate allows Privilege Escalation via unrestricted search_path during migration_CVE-2025-55282

aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that allows a user to elevate t...

aiven aiven-db-migrate < 1.0.7 CVE