Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-30124

CVE-2025-30124_CVE-2025-30124

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is writte...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-30125

CVE-2025-30125_CVE-2025-30125

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which c...

n/a n/a n/a CVE
CRITICAL 9.3 CVE-2025-53696

CVE-2025-53696_CVE-2025-53696

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware pa...

Johnson Controls, Inc iSTAR Ultra CVE
CRITICAL 9.8 CVE-2025-54418

CodeIgniter4’s ImageMagick Handler has Command Injection Vulnerability_CVE-2025-54418

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use t...

codeigniter4 CodeIgniter4 < 4.6.2 CVE
CRITICAL 9.4 CVE-2025-54299

Extension – nobossextensions.com – Stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla_CVE-2025-54299

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

nobossextensions.com No Boss Testimonials component for Joomla 4.0.0-4.0.2 CVE
CRITICAL 9.4 CVE-2025-54298

Extension – firecoders.com – Stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla_CVE-2025-54298

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

firecoders.com CommentBox component for Joomla 1.0.0-1.1.0 CVE
CRITICAL 10 CVE-2025-54419

Node-SAML Contains SAML Signature Verification Vulnerability_CVE-2025-54419

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original resp...

node-saml node-saml = 5.0.1 CVE
CRITICAL 9.9 CVE-2025-54426

Polkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed points_CVE-2025-54426

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and...

polkadot-evm frontier < 36f70d1 CVE
CRITICAL 9.8 CVE-2025-54428

RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)_CVE-2025-54428

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions bel...

musombi123 RevelaCode-Backend < 1.0.1 CVE
CRITICAL 9 CVE-2025-8264

CVE-2025-8264_CVE-2025-8264

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attac...

n/a z-push/z-push-dev CVE