Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-48913

Apache CXF: Untrusted JMS configuration can lead to RCE_CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution c...

Apache Software Foundation Apache CXF 4.1.0 CVE
CRITICAL 9.8 CVE-2025-53606

Apache Seata (incubating): Deserialization of untrusted Data in Apache Seata Server_CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are reco...

Apache Software Foundation Apache Seata (incubating) 2.4.0 CVE
CRITICAL 9.8 CVE-2025-52913

CVE-2025-52913_CVE-2025-52913

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attack...

N/A N/A CVE
CRITICAL 9.8 CVE-2025-5095

Burk Technology ARC Solo Missing Authentication for Critical Function_CVE-2025-5095

Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over t...

Burk Technology ARC Solo CVE
CRITICAL 9.8 CVE-2025-8284

Packet Power EMX and EG Missing Authentication for Critical Function_CVE-2025-8284

By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauth...

Packet Power EMX CVE
CRITICAL 9.3 CVE-2025-8731

TRENDnet TI-G160i/TI-PG102i/TPL-430AP SSH Service default credentials_CVE-2025-8731

A vulnerability was found in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. It has been classified as critical. This affects an unknown...

TRENDnet TI-G160i 20250724 CVE
CRITICAL 9.8 CVE-2025-8356

Path Traversal leading to RCE_CVE-2025-8356

In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized files on the server. This can l...

Xerox FreeFlow Core CVE
CRITICAL 9.3 CVE-2025-8730

Belkin F9K1009/F9K1010 Web Interface hard-coded credentials_CVE-2025-8730

A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this issue is some unknown function...

Belkin F9K1009 2.00.04 CVE
CRITICAL 9.1 CVE-2025-54887

jwe: Missing AES-GCM authentication tag validation in encrypted JWEs_CVE-2025-54887

jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentication tags of encrypted JWEs...

jwt ruby-jwe < 1.1.1 CVE
CRITICAL 9.1 MS:CVE-2025-53792

Azure Portal Elevation of Privilege Vulnerability_MS:CVE-2025-53792

{“lastseen”:”2025-08-07T22:54:54″,”description”:””,”published”:”2025-08-07T07:00:...

N/A N/A MSCVE