Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2025-54127

HAXcms’s Insecure Default Configuration Leads to Unauthenticated Access_CVE-2025-54127

HAXcms with nodejs backend allows users to start the server in any HAXsite or HAXcms instance. In versions 11.0.6 and below, the NodeJS version of ...

haxtheweb issues < 11.0.7 CVE
CRITICAL 9.8 CVE-2025-6187

bSecure 1.3.7 – 1.7.9 – Missing Authorization to Unauthenticated Privilege Escalation via order_info REST Endpoint_CVE-2025-6187

The bSecure plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization within its order_info REST endpoint in versions...

bsecuretech bSecure – Your Universal Checkout 1.3.7 CVE
CRITICAL 10 CVE-2025-4285

SQLi in Rolantis Information Technologies’ Agentis_CVE-2025-4285

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rolantis Information Technologies Agentis all...

Rolantis Information Technologies Agentis CVE
CRITICAL 9.3 CVE-2025-34143

ETQ Reliance CG Authentication Bypass via Trailing Space RCE_CVE-2025-34143

An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login as the privileged internal...

ETQ Reliance CG (legacy) * CVE
CRITICAL 9.8 CVE-2025-8044

CVE-2025-8044_CVE-2025-8044

Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption and we presume that with eno...

Mozilla Firefox unspecified CVE
CRITICAL 9.8 CVE-2025-8043

CVE-2025-8043_CVE-2025-8043

Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability affects Firefox < 141 and Thunderbird < 141.

Mozilla Firefox unspecified CVE
CRITICAL 9.8 CVE-2025-8038

CVE-2025-8038_CVE-2025-8038

Firefox ignored paths when checking the validity of navigations in a frame. This vulnerability affects Firefox < 141, Firefox ESR < 140.1, Thunderb...

Mozilla Firefox unspecified CVE
CRITICAL 9.1 CVE-2025-8037

CVE-2025-8037_CVE-2025-8037

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed c...

Mozilla Firefox unspecified CVE
CRITICAL 9.8 CVE-2025-8031

CVE-2025-8031_CVE-2025-8031

The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authentication credentials. This vu...

Mozilla Firefox unspecified CVE
CRITICAL 9.8 CVE-2025-8028

CVE-2025-8028_CVE-2025-8028

On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction causing truncation and inc...

Mozilla Firefox unspecified CVE