Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-46121

CVE-2025-46121_CVE-2025-46121

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the functions `stamgr_cfg_adpt_addStaFavou...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-46120

CVE-2025-46120_CVE-2025-46120

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.1.0.282...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-44658

CVE-2025-44658_CVE-2025-44658

In Netgear RAX30 V1.0.10.94, a PHP-FPM misconfiguration vulnerability is caused by not following the specification to only limit FPM to .php extens...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-44655

CVE-2025-44655_CVE-2025-44655

In TOTOLink A7100RU V7.4, A950RG V5.9, and T10 V5.9, the chroot_local_user option is enabled in the vsftpd.conf. This could lead to unauthorized ac...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-7393

Mail Login – Critical – Access bypass – SA-CONTRIB-2025-088_CVE-2025-7393

Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Mail Login allows Brute Force.This issue affects Mail Login: from...

Drupal Mail Login 3.0.0 CVE
CRITICAL 9.8 CVE-2025-44654

CVE-2025-44654_CVE-2025-44654

In Linksys E2500 3.0.04.002, the chroot_local_user option is enabled in the vsftpd configuration file. This could lead to unauthorized access to sy...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-36846

CVE-2025-36846_CVE-2025-36846

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-52362

CVE-2025-52362_CVE-2025-52362

Server-Side Request Forgery (SSRF) vulnerability exists in the URL processing functionality of PHProxy version 1.1.1 and prior. The input validatio...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-54071

RomM’s authenticated arbitrary file write vulnerability can lead to Remote Code Execution_CVE-2025-54071

RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface. In versions 4.0.0-be...

rommapp romm < 4.0.0-beta.4 CVE
CRITICAL 10 CVE-2025-54122

Manager-io/Manager allows unauthenticated full read server-side request forgery in “proxy” endpoint_CVE-2025-54122

Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identifie...

Manager-io Manager < 25.7.21.2525 CVE