Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.7 CVE-2025-58357

5ire Chat Message XSS Vulnerability Enables Remote Code Execution_CVE-2025-58357

5ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 contains a vulnerability in th...

nanbingxyz 5ire >= 0.13.2, < 0.14.0 CVE
CRITICAL 9.8 CVE-2025-26416

CVE-2025-26416_CVE-2025-26416

In initializeSwizzler of SkBmpStandardCodec.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote e...

Google Android 15 CVE
CRITICAL 9.8 CVE-2025-22435

CVE-2025-22435_CVE-2025-22435

In avdt_msg_ind of avdt_msg.cc, there is a possible memory corruption due to type confusion. This could lead to paired device escalation of privile...

Google Android 15 CVE
CRITICAL 9.8 CVE-2025-22429

CVE-2025-22429_CVE-2025-22429

In multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of p...

Google Android 15 CVE
CRITICAL 9.8 CVE-2025-57052

CVE-2025-57052_CVE-2025-57052

cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c, allowing remote attackers...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-57148

CVE-2025-57148_CVE-2025-57148

phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the lack of extension validation.

n/a n/a n/a CVE
CRITICAL 9.3 CVE-2025-55747

XWiki Platform’s configuration files can be accessed through the webjars API_CVE-2025-55747

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 6.1-milestone-2 through 16.10...

xwiki xwiki-platform >= 6.1-milestone-2, < 16.10.7 CVE
CRITICAL 9.3 CVE-2025-55748

XWiki Platform’s configuration files can be accessed through jsx and sx endpoints_CVE-2025-55748

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2-milestone-2 through 16.10....

xwiki xwiki-platform >= 4.2-milestone-2, < 16.10.7 CVE
CRITICAL 9 CVE-2025-53690

Sitecore Products ViewState Deserialization Vulnerability_CVE-2025-53690

Deserialization of Untrusted Data vulnerability in Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Code Injection.This i...

Sitecore Experience Manager (XM) CVE
CRITICAL 9.4 CVE-2025-56752

CVE-2025-56752_CVE-2025-56752

A vulnerability in the Ruijie RG-ES series switch firmware ESW_1.0(1)B1P39 enables remote attackers to fully bypass authentication mechanisms, prov...

n/a n/a n/a CVE