Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-46001

CVE-2025-46001_CVE-2025-46001

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via ...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-54079

WeGIA vulnerable to SQL Injection (Blind Time-Based) in endpoint ‘Profile_Atendido.php’ parameter ‘idatendido’_CVE-2025-54079

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identifi...

LabRedesCefetRJ WeGIA < 3.4.6 CVE
CRITICAL 9.8 CVE-2025-51452

CVE-2025-51452_CVE-2025-51452

In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

n/a n/a n/a CVE
CRITICAL 9.3 CVE-2025-7353

Rockwell Automation ControlLogix® Ethernet Remote Code Execution Vulnerability_CVE-2025-7353

A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific IP address...

Rockwell Automation 1756-EN2T/D Version 11.004 or below CVE
CRITICAL 9.9 CVE-2025-49747

Azure Machine Learning Elevation of Privilege Vulnerability_CVE-2025-49747

{“lastseen”:””,”description”:””,”published”:”2025-07-18T17:04:44.003Z”,&#82...

Microsoft Azure Machine Learning N/A CVE
CRITICAL 9.9 CVE-2025-49746

Azure Machine Learning Elevation of Privilege Vulnerability_CVE-2025-49746

{“lastseen”:””,”description”:””,”published”:”2025-07-18T17:04:44.617Z”,&#82...

Microsoft Azure Machine Learning N/A CVE
CRITICAL 9 CVE-2025-47158

Azure DevOps Server Elevation of Privilege Vulnerability_CVE-2025-47158

{“lastseen”:””,”description”:””,”published”:”2025-07-18T17:04:45.914Z”,&#82...

Microsoft Azure DevOps N/A CVE
CRITICAL 9 CVE-2025-54309

CVE-2025-54309_CVE-2025-54309

CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote...

CrushFTP CrushFTP 10 CVE
CRITICAL 9.2 CVE-2025-7395

Domain Name Validation Bypass with Apple Native Certificate Validation_CVE-2025-7395

A certificate verification error in wolfSSL when building with the WOLFSSL_SYS_CA_CERTS and WOLFSSL_APPLE_NATIVE_CERT_VALIDATION options results in...

wolfSSL wolfSSL 5.6.4 CVE
CRITICAL 9.4 CVE-2025-29757

CVE-2025-29757_CVE-2025-29757

An incorrect authorisation check in the the 'plant transfer' function of the Growatt cloud service allowed a malicous attacker with a valid account...

Growatt https://oss.growatt.com CVE