Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-26855

Extension – joomcar.net – SQL injection in Articles Calendar 1.0.0 – 1.0.1.0007 for Joomla_CVE-2025-26855

A SQL injection in Articles Calendar extension 1.0.0 - 1.0.1.0007 for Joomla allows attackers to execute arbitrary SQL commands.

joomcar.net Articles Calendar extension for Joomla 1.0.0-1.0.1.0007 CVE
CRITICAL 9.8 CVE-2025-26854

Extension – joomcar.net – SQL injection in Articles Good Search 1.0.0 – 1.2.4.0011 for Joomla_CVE-2025-26854

A SQL injection in Articles Good Search extension 1.0.0 - 1.2.4.0011 for Joomla allows attackers to execute arbitrary SQL commands.

joomcar.net Articles Good Search extension for Joomla 1.0.0-1.2.4.0011 CVE
CRITICAL 9.8 CVE-2025-7444

LoginPress Pro <= 5.0.1 - Authentication Bypass via WordPress.com OAuth provider_CVE-2025-7444

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.0.1. This is due to insuffic...

LoginPress LoginPress Pro * CVE
CRITICAL 9.8 CVE-2025-46001

CVE-2025-46001_CVE-2025-46001

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via ...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-54079

WeGIA vulnerable to SQL Injection (Blind Time-Based) in endpoint ‘Profile_Atendido.php’ parameter ‘idatendido’_CVE-2025-54079

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identifi...

LabRedesCefetRJ WeGIA < 3.4.6 CVE
CRITICAL 9.8 CVE-2025-51452

CVE-2025-51452_CVE-2025-51452

In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

n/a n/a n/a CVE
CRITICAL 9.3 CVE-2025-7353

Rockwell Automation ControlLogix® Ethernet Remote Code Execution Vulnerability_CVE-2025-7353

A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific IP address...

Rockwell Automation 1756-EN2T/D Version 11.004 or below CVE
CRITICAL 9.9 CVE-2025-49747

Azure Machine Learning Elevation of Privilege Vulnerability_CVE-2025-49747

{“lastseen”:””,”description”:””,”published”:”2025-07-18T17:04:44.003Z”,&#82...

Microsoft Azure Machine Learning N/A CVE
CRITICAL 9.9 CVE-2025-49746

Azure Machine Learning Elevation of Privilege Vulnerability_CVE-2025-49746

{“lastseen”:””,”description”:””,”published”:”2025-07-18T17:04:44.617Z”,&#82...

Microsoft Azure Machine Learning N/A CVE
CRITICAL 9 CVE-2025-47158

Azure DevOps Server Elevation of Privilege Vulnerability_CVE-2025-47158

{“lastseen”:””,”description”:””,”published”:”2025-07-18T17:04:45.914Z”,&#82...

Microsoft Azure DevOps N/A CVE