Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.2 CVE-2025-54068

Livewire vulnerable to remote command execution during property update hydration_CVE-2025-54068

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achi...

livewire livewire >= 3.0.0-beta.1, < 3.6.4 CVE
CRITICAL 9 CVE-2025-23266

CVE-2025-23266_CVE-2025-23266

NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute...

NVIDIA Container Toolkit NVIDIA Container Toolkit All versions up to and including 1.17.7 (CDI mode only for versions prior to 1.17.5) CVE
CRITICAL 9.6 CVE-2025-53964

CVE-2025-53964_CVE-2025-53964

GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary and then s...

n/a n/a n/a CVE
CRITICAL 9.3 CVE-2025-6185

Leviton AcquiSuite and Energy Monitoring Hub Cross-site Scripting_CVE-2025-6185

Leviton AcquiSuite and Energy Monitoring Hub are susceptible to a cross-site scripting vulnerability, allowing an attacker to craft a malicious p...

Leviton AcquiSuite Version A8810 CVE
CRITICAL 9.8 CVE-2025-6222

WooCommerce Refund And Exchange with RMA – Warranty Management, Refund Policy, Manage User Wallet <= 3.2.6 - Unauthenticated Arbitrary File Upload_CVE-2025-6222

The WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet theme for WordPress is vulnerable to arbitrar...

WP Swings WooCommerce Refund And Exchange with RMA - Warranty Management, Refund Policy, Manage User Wallet * CVE
CRITICAL 9.8 CVE-2025-26855

Extension – joomcar.net – SQL injection in Articles Calendar 1.0.0 – 1.0.1.0007 for Joomla_CVE-2025-26855

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

joomcar.net Articles Calendar extension for Joomla 1.0.0-1.0.1.0007 CVE
CRITICAL 9.8 CVE-2025-26854

Extension – joomcar.net – SQL injection in Articles Good Search 1.0.0 – 1.2.4.0011 for Joomla_CVE-2025-26854

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

joomcar.net Articles Good Search extension for Joomla 1.0.0-1.2.4.0011 CVE
CRITICAL 9.8 CVE-2025-7444

LoginPress Pro <= 5.0.1 - Authentication Bypass via WordPress.com OAuth provider_CVE-2025-7444

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insuffic...

LoginPress LoginPress Pro * CVE
CRITICAL 9.8 CVE-2025-46001

CVE-2025-46001_CVE-2025-46001

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via ...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-54079

WeGIA vulnerable to SQL Injection (Blind Time-Based) in endpoint ‘Profile_Atendido.php’ parameter ‘idatendido’_CVE-2025-54079

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identifi...

LabRedesCefetRJ WeGIA < 3.4.6 CVE