Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-54418

CodeIgniter4’s ImageMagick Handler has Command Injection Vulnerability_CVE-2025-54418

CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use t...

codeigniter4 CodeIgniter4 < 4.6.2 CVE
CRITICAL 9.4 CVE-2025-54299

Extension – nobossextensions.com – Stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla_CVE-2025-54299

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

nobossextensions.com No Boss Testimonials component for Joomla 4.0.0-4.0.2 CVE
CRITICAL 9.4 CVE-2025-54298

Extension – firecoders.com – Stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla_CVE-2025-54298

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

firecoders.com CommentBox component for Joomla 1.0.0-1.1.0 CVE
CRITICAL 10 CVE-2025-54419

Node-SAML Contains SAML Signature Verification Vulnerability_CVE-2025-54419

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original resp...

node-saml node-saml = 5.0.1 CVE
CRITICAL 9.9 CVE-2025-54426

Polkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed points_CVE-2025-54426

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and...

polkadot-evm frontier < 36f70d1 CVE
CRITICAL 9.8 CVE-2025-54428

RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)_CVE-2025-54428

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions bel...

musombi123 RevelaCode-Backend < 1.0.1 CVE
CRITICAL 9 CVE-2025-8264

CVE-2025-8264_CVE-2025-8264

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attac...

n/a z-push/z-push-dev CVE
CRITICAL 9.8 CVE-2025-50738

CVE-2025-50738_CVE-2025-50738

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing ...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-44136

CVE-2025-44136_CVE-2025-44136

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html e...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-40600

CVE-2025-40600_CVE-2025-40600

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service...

SonicWall SonicOS 7.2.0-7015 and older versions CVE