Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2025-50754

CVE-2025-50754_CVE-2025-50754

Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A malicious script submitted by a...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-51387

CVE-2025-51387_CVE-2025-51387

The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure ...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-27212

CVE-2025-27212_CVE-2025-27212

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access manag...

Ubiquiti Inc UniFi Access Reader Pro 2.15.9 CVE
CRITICAL 9.9 CVE-2025-46093

CVE-2025-46093_CVE-2025-46093

LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by...

LiquidFiles LiquidFiles CVE
CRITICAL 9.8 CVE-2025-54802

pyLoad CNL Blueprint is vulnerable to Path Traversal through `dlc_path` leading to Remote Code Execution (RCE)_CVE-2025-54802

pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there is an opportunity for path t...

pyload pyload >= 0.5.0b3.dev89, < 0.5.0b3.dev90 CVE
CRITICAL 10 CVE-2025-54119

ADOdb’s sqlite3 driver allows SQL injection_CVE-2025-54119

ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versions 5.22.9 and below, impro...

ADOdb ADOdb < 5.22.10 CVE
CRITICAL 9.3 CVE-2025-53417

File Parsing Deserialization of Untrusted Data in DTM Soft_CVE-2025-53417

DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability

Delta Electronics DIAView CVE
CRITICAL 9.6 CVE-2025-54982

SAML 2.0 Public Key Validation Issue_CVE-2025-54982

An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowed an authentication abuse.

Zscaler Authentication Server CVE
CRITICAL 9.4 CVE-2025-54987

CVE-2025-54987_CVE-2025-54987

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code an...

Trend Micro, Inc. Trend Micro Apex One 2019 (14.0) CVE
CRITICAL 9.4 CVE-2025-54948

CVE-2025-54948_CVE-2025-54948

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code an...

Trend Micro, Inc. Trend Micro Apex One 2019 (14.0) CVE