Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 CVE-2025-54415

dag-factory’s CI/CD Workflow Allows for Repository Takeover and Secret Exfiltration_CVE-2025-54415

dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0a8 and below, a high-severi...

astronomer dag-factory < 0.23.0a9 CVE
CRITICAL 9.8 CVE-2025-6895

MelaPress Login Security 2.1.0 – 2.1.1 – Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function_CVE-2025-6895

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_bas...

melapress Melapress Login Security 2.1.0 CVE
CRITICAL 9.8 CVE-2025-6918

SQLi in Ncvav’s Virtual PBX Software_CVE-2025-6918

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injecti...

Ncvav Virtual PBX Software CVE
CRITICAL 9.3 CVE-2025-27724

CVE-2025-27724_CVE-2025-27724

A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php fi...

MedDream MedDream PACS Premium 7.3.3.840 CVE
CRITICAL 9.3 CVE-2025-26469

CVE-2025-26469_CVE-2025-26469

An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. ...

MedDream MedDream PACS Premium 7.3.3.840 CVE
CRITICAL 9.8 CVE-2025-30133

CVE-2025-30133_CVE-2025-30133

An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires device registration via the "IRO...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-53695

CVE-2025-53695_CVE-2025-53695

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to ...

Johnson Controls, Inc iSTAR Ultra CVE
CRITICAL 9.8 CVE-2025-30124

CVE-2025-30124_CVE-2025-30124

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password is writte...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-30125

CVE-2025-30125_CVE-2025-30125

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default credentials of 12345678, which c...

n/a n/a n/a CVE
CRITICAL 9.3 CVE-2025-53696

CVE-2025-53696_CVE-2025-53696

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware pa...

Johnson Controls, Inc iSTAR Ultra CVE