Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2025-27217

CVE-2025-27217_CVE-2025-27217

A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP ...

Ubiquiti Inc UISP Application 2.4.220 CVE
CRITICAL 9.8 CVE-2025-24285

CVE-2025-24285_CVE-2025-24285

Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network...

Ubiquiti Inc UniFi Connect EV Station Lite 1.5.2 CVE
CRITICAL 10 CVE-2025-34158

Plex Media Server (PMS) 1.41.7.x – 1.42.0.x Unspecified Vulnerabiliity_CVE-2025-34158

Plex Media Server (PMS) versions 1.41.7.x through 1.42.0.x are affected by an unspecified security vulnerability reported via Plex’s bug bounty pro...

Plex, Inc. Plex Media Server 1.41.7.x CVE
CRITICAL 9.8 CVE-2025-50904

CVE-2025-50904_CVE-2025-50904

There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-55444

CVE-2025-55444_CVE-2025-55444

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote ...

n/a n/a n/a CVE
CRITICAL 9.8 7B41EE7B-2748-

Exploit for Incorrect Authorization in Apache Shiro_7B41EE7B-2748-5521-8823-01E419A5730A

Apache Shiro CVE-2022-32532 复现环境 这是一个用于复现 CVE-2022-32532(Apache Shiro RegExPatternMatcher 认证绕过)的最小化 Web 应用。...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 7D5B07AF-EAEE-

Exploit for Code Injection in Craftcms Craft_Cms_7D5B07AF-EAEE-5814-B0D1-79478A43DC2A

CVE-2023-41892_poc Customized this for my own use poc_noauth.py 기본 PHP 원라인 웹쉘 ?cmd= 통한 OS 명령어 실행 poc_auth.py 간단한 키 기반 인증이...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2025-8895

WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File Copy_CVE-2025-8895

The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, a...

cozmoslabs WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress * CVE
CRITICAL 9.1 CVE-2025-7390

Bypass the client certificate trust check of an opc.https server while only secure communication is allowed_CVE-2025-7390

A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure...

Softing Industrial Automation GmbH OPC UA C++ SDK 6.40 CVE
CRITICAL 9.8 CVE-2025-9187

CVE-2025-9187_CVE-2025-9187

Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that with eno...

Mozilla Firefox unspecified CVE