Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 5E7E3637-A48D-

Exploit for Code Injection in Codecentric Spring_Boot_Admin_5E7E3637-A48D-5AA5-9B73-0DC6A9C35728

codecentric's Spring Boot Admin =============================== [![Apache License 2](https://img.shields.io/badge/license-ASF2-blue.svg)](https://w...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 EDEE5D1B-C9A2-

Exploit for UNIX Symbolic Link Following in Codehaus-Plexus Plexus-Archiver_EDEE5D1B-C9A2-5BFC-97ED-7E4C5A1C67C4

Plexus-archiver The current master is now at https://github.com/codehaus-plexus/plexus-archiver Important Hint Based on a hint of snyk.io secur...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 93864F83-CFF8-

Exploit for Code Injection in Sqlite_Jdbc_Project Sqlite_Jdbc_93864F83-CFF8-5A2A-864A-1333E2D80703

SQLite JDBC Driver SQLite JDBC is a library for accessing and creating SQLite database files in Java. Our SQLiteJDBC library requires no confi...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 12158E32-3B75-

Exploit for Code Injection in Apache Rocketmq_12158E32-3B75-593B-BE77-22BAB4BF0B0D

Apache RocketMQ [![Build Status][maven-build-image]][maven-build-url] [![CodeCov][codecov-image]][codecov-url] [![Maven Central][maven-central-imag...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 D1522323-B251-

Exploit for CVE-2025-54253_D1522323-B251-5226-B2A3-59C86FCBD94E

CVE-2025-54253 Adobe AEM OGNL Injection Simulated PoC Lab Table of contents - Overview - What this repository contains - Goals - Threat model - S...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 473D5F33-8E0F-

Exploit for Path Traversal in Redhat Keycloak_473D5F33-8E0F-59CD-BA58-8F320A6DA42E

Keycloak Keycloak is an Open Source Identity and Access Management solution for modern Applications and Services. This repository contains the sour...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 6B223B9E-1BCC-

Exploit for Improper Privilege Management in Najeebmedia Simple_User_Registration_6B223B9E-1BCC-5F2C-AA56-7E6507045974

CVE-2025-4334 - Simple User Registration --form ``` Arguments: -u / --url → Base WordPress URL (e.g. https://target.com/wordpress/) --form → Full...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 5B52B1EC-F6BA-

Exploit for CVE-2025-49132_5B52B1EC-F6BA-5508-970F-5FC58BCD3A03

CVE-2025-49132 PoC (Improved) This is an improved version of the CVE-2025-49132 proof of concept exploit. CVE Information CVE ID: CVE-2025-49132 N...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2025-55591

CVE-2025-55591_CVE-2025-55591

TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapDel endp...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-55293

Meshtastic allows crafting of specific NodeInfo packets that overwrite any publicKey saved in the NodeDB_CVE-2025-55293

Meshtastic is an open source mesh networking solution. Prior to v2.6.3, an attacker can send NodeInfo with a empty publicKey first, then overwrite ...

meshtastic firmware < 2.6.3 CVE