Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2 CVE-2025-9309

Tenda AC10 MD5 Hash shadow hard-coded credentials_CVE-2025-9309

A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file /etc_ro/shadow of the component MD5 Hash Handler. ...

Tenda AC10 16.03.10.13 CVE
LOW 3.5 CVE-2025-47700

AI plugin APIs can be triggered using post actions_CVE-2025-47700

Mattermost Server versions 10.5.x

Mattermost Mattermost 10.10.0 CVE
LOW 3.8 CVE-2025-53971

Channel and Team Membership APIs inadvertently allow loss of Member privileges._CVE-2025-53971

Mattermost versions 10.5.x

Mattermost Mattermost 10.5.0 CVE
LOW 3.5 CVE-2025-49810

Thread summarization allows persistent access to channel_CVE-2025-49810

Mattermost versions 10.5.x

Mattermost Mattermost 10.5.0 CVE
LOW 3.6 22BBAA8D-F2E8-

Exploit for Link Following in 7-Zip_22BBAA8D-F2E8-5CE3-865A-9B091906FF57

🔒 CVE-2025-55188-7z-exploit - Easy Steps to Download and Run 🚀 Getting Started Welcome to CVE-2025-55188-7z-exploit!...

N/A N/A GITHUBEXPLOIT
LOW 2.3 CVE-2025-8448

CVE-2025-8448_CVE-2025-8448

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could cause unauthorized access to sensitive credenti...

Schneider Eelctric EcoStruxureTM Building Operation Enterprise Server Versions prior to 7.0.1 CVE
LOW 2.7 CVE-2025-2988

IBM Sterling B2B Integrator and IBM Sterling File Gateway information disclosure_CVE-2025-2988

IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive se...

IBM Sterling B2B Integrator 6.0.0.0 CVE
LOW 2.4 CVE-2025-54411

Discourse welcome banner user name XSS_CVE-2025-54411

Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect...

discourse discourse < 3.5.0.beta8 CVE
LOW 2 CVE-2025-3639

CVE-2025-3639_CVE-2025-3639

Liferay Portal 7.3.0 through 7.4.3.132, and Liferay DXP 2025.Q1 through 2025.Q1.6, 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024....

Liferay Portal 7.3.0 CVE
LOW 2.2 CVE-2025-54234

ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)_CVE-2025-54234

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to limi...

Adobe ColdFusion CVE