Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2025-50128

CVE-2025-50128_CVE-2025-50128

A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commi...

WWBN AVideo 14.4 CVE
CRITICAL 9.6 CVE-2025-46410

CVE-2025-46410_CVE-2025-46410

A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev ...

WWBN AVideo 14.4 CVE
CRITICAL 9.6 CVE-2025-41420

CVE-2025-41420_CVE-2025-41420

A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a89...

WWBN AVideo 14.4 CVE
CRITICAL 9.3 CVE-2025-6260

Network Thermostat X-Series WiFi Thermostats Missing Authentication for Critical Function_CVE-2025-6260

The embedded web server on the thermostat listed version ranges contain a vulnerability that allows unauthenticated attackers, either on the local ...

Network Thermostat X-Series WiFi thermostats v4.5 CVE
CRITICAL 9.3 CVE-2025-32429

XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter_CVE-2025-32429

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 9.4-rc-1 through 16.10.5 and 1...

xwiki xwiki-platform >= 9.4-rc-1, < 16.10.6 CVE
CRITICAL 9.8 CVE-2025-45777

CVE-2025-45777_CVE-2025-45777

An issue in the OTP mechanism of Chavara Family Welfare Centre Chavara Matrimony Site v2.0 allows attackers to bypass authentication via supplying ...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-29631

CVE-2025-29631_CVE-2025-29631

An issue in Gardyn 4 allows a remote attacker execute arbitrary code

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-46199

CVE-2025-46199_CVE-2025-46199

Cross Site Scripting vulnerability in grav v.1.7.48 and before allows an attacker to execute arbitrary code via a crafted script to the form fields

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-30135

CVE-2025-30135_CVE-2025-30135

An issue was discovered on IROAD Dashcam FX2 devices. Dumping Files Over HTTP and RTSP Without Authentication can occur. It lacks authentication co...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-54416

tj-actions/branch-names Contains Command Injection Vulnerability_CVE-2025-54416

tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with support for all events. In vers...

tj-actions branch-names < 9.0.0 CVE