Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-50475

CVE-2025-50475_CVE-2025-50475

An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitra...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-26063

CVE-2025-26063_CVE-2025-26063

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload i...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-26062

CVE-2025-26062_CVE-2025-26062

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obt...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-8286

Güralp Systems Güralp FMUS series Missing Authentication for Critical Function_CVE-2025-8286

Güralp FMUS series seismic monitoring devices expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify...

Güralp Systems Güralp FMUS Series Seismic Monitoring Devices All versions CVE
CRITICAL 9.8 CVE-2025-5954

Service Finder SMS System <= 2.0.0 - Unauthenticated Privilege Escalation_CVE-2025-5954

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including,...

aonetheme Service Finder SMS System * CVE
CRITICAL 9.8 CVE-2025-5947

Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie_CVE-2025-5947

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and includi...

aonetheme Service Finder Bookings * CVE
CRITICAL 9.8 CVE-2025-8454

CVE-2025-8454_CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts t...

Debian devscripts CVE
CRITICAL 9.8 CVE-2025-50460

CVE-2025-50460_CVE-2025-50460

A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.l...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-52390

CVE-2025-52390_CVE-2025-52390

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-50472

CVE-2025-50472_CVE-2025-50472

The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_mod...

n/a n/a n/a CVE