Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-7437

Ebook Store <= 5.8012 - Unauthenticated Arbitrary File Upload_CVE-2025-7437

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form funct...

motovnet Ebook Store * CVE
CRITICAL 10 CVE-2025-41240

Mounted Kubernetes Secrets under a predictable path located within the web server document root_CVE-2025-41240

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document...

VMware bitnamicharts/appsmith 21.2.0 CVE
CRITICAL 10 CVE-2025-5243

Arbitrary File Upload in SMG Software’s Information Portal_CVE-2025-5243

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnera...

SMG Software Information Portal CVE
CRITICAL 9.8 CVE-2025-4822

SQLi in Bayraktar Solar Energies’ ScadaWatt Otopilot_CVE-2025-4822

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot a...

Bayraktar Solar Energies ScadaWatt Otopilot CVE
CRITICAL 9.8 CVE-2025-4784

SQLi in Moderec’s Tourtella_CVE-2025-4784

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This i...

Moderec Tourtella CVE
CRITICAL 9 CVE-2025-53084

CVE-2025-53084_CVE-2025-53084

A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff...

WWBN AVideo 14.4 CVE
CRITICAL 9.6 CVE-2025-50128

CVE-2025-50128_CVE-2025-50128

A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commi...

WWBN AVideo 14.4 CVE
CRITICAL 9.6 CVE-2025-46410

CVE-2025-46410_CVE-2025-46410

A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev ...

WWBN AVideo 14.4 CVE
CRITICAL 9.6 CVE-2025-41420

CVE-2025-41420_CVE-2025-41420

A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a89...

WWBN AVideo 14.4 CVE
CRITICAL 9.3 CVE-2025-6260

Network Thermostat X-Series WiFi Thermostats Missing Authentication for Critical Function_CVE-2025-6260

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local ...

Network Thermostat X-Series WiFi thermostats v4.5 CVE