Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-45150

CVE-2025-45150_CVE-2025-45150

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a craf...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-50870

CVE-2025-50870_CVE-2025-50870

Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-6000

Arbitrary Remote Code Execution via Plugin Catalog Abuse_CVE-2025-6000

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a ...

HashiCorp Vault 0.8.0 CVE
CRITICAL 9.3 CVE-2025-54574

Squid’s URN Handling can lead to Buffer Overflow_CVE-2025-54574

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution a...

squid-cache squid < 6.4 CVE
CRITICAL 9.3 CVE-2025-54792

LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception_CVE-2025-54792

LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection...

localsend localsend <= 1.17.0 CVE
CRITICAL 9.2 CVE-2025-54790

Files: Potential for SQL Injection through File Browse and List Operations_CVE-2025-54790

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploi...

humhub cfiles < 0.16.10 CVE
CRITICAL 9.4 CVE-2025-54782

@nestjs/devtools-integration’s CSRF to Sandbox Escape Allows for RCE against JS Developers_CVE-2025-54782

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vul...

nestjs nest < 0.2.1 CVE
CRITICAL 9.8 CVE-2025-6077

CVE-2025-6077_CVE-2025-6077

Partner Software's Partner Software Product and corresponding Partner Web application use the same default username and password for the administra...

Partner Software Partner Web 4.32 CVE
CRITICAL 9.8 CVE-2025-7710

Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator_CVE-2025-7710

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is ...

Brave Brave Conversion Engine (PRO) * CVE
CRITICAL 9.1 CVE-2025-6205

Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025_CVE-2025-6205

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged acc...

Dassault Systèmes DELMIA Apriso Release 2020 Golden CVE