Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.2 CVE-2025-8070

Windows service registered with an unquoted ImagePath vulnerability in the system registry_CVE-2025-8070

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allows a local attacker to execu...

ASUSTOR ABP and AES ABP 2.0 CVE
CRITICAL 9.8 CVE-2025-41687

Weidmueller: Unauthenticated Stack-Based Buffer Overflow in u-link Management API_CVE-2025-41687

An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected devices.

Weidmueller IE-SR-2TX-WL V0.0 CVE
CRITICAL 9.3 CVE-2025-54294

Extension – stackideas.com – SQLi vulnerability in Komento component 4.0.0-4.0.7 for Joomla_CVE-2025-54294

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered. The issue allows unprivileged users to execute arbitrary SQL commands.

stackideas.com Komento component for Joomla 4.0.0-4.0.7 CVE
CRITICAL 9.8 CVE-2025-7852

WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function_CVE-2025-7852

The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the image_upload_handle() function...

iqonicdesign WPBookit * CVE
CRITICAL 9.8 CVE-2025-7437

Ebook Store <= 5.8012 - Unauthenticated Arbitrary File Upload_CVE-2025-7437

The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form funct...

motovnet Ebook Store * CVE
CRITICAL 10 CVE-2025-41240

Mounted Kubernetes Secrets under a predictable path located within the web server document root_CVE-2025-41240

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document...

VMware bitnamicharts/appsmith 21.2.0 CVE
CRITICAL 10 CVE-2025-5243

Arbitrary File Upload in SMG Software’s Information Portal_CVE-2025-5243

Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnera...

SMG Software Information Portal CVE
CRITICAL 9.8 CVE-2025-4822

SQLi in Bayraktar Solar Energies’ ScadaWatt Otopilot_CVE-2025-4822

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bayraktar Solar Energies ScadaWatt Otopilot a...

Bayraktar Solar Energies ScadaWatt Otopilot CVE
CRITICAL 9.8 CVE-2025-4784

SQLi in Moderec’s Tourtella_CVE-2025-4784

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Moderec Tourtella allows SQL Injection.This i...

Moderec Tourtella CVE
CRITICAL 9 CVE-2025-53084

CVE-2025-53084_CVE-2025-53084

A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff...

WWBN AVideo 14.4 CVE