Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.1 THN:50187FD5FB6...

CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials_THN:50187FD5FB6B5CD808824E35A5E63ED8

![](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAQAAAC1HAwCAAAAC0lEQVR42mP8Xw8AAoMBgDTD2qgAAAAASUVORK5CYII=) Cybersecurity researchers ...

N/A N/A THN
CRITICAL 9.1 CVE-2025-54997

OpenBao: Privileged Operator May Execute Code on the Underlying Host_CVE-2025-54997

OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In version...

openbao openbao < 2.3.2 CVE
CRITICAL 10 CVE-2025-55013

Assemblyline 4 Service Client: Arbitrary Write through path traversal in Client code_CVE-2025-55013

The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below ...

CybercentreCanada assemblyline < 4.6.1.dev138 CVE
CRITICAL 9.8 CVE-2025-50692

CVE-2025-50692_CVE-2025-50692

FoxCMS

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-54952

CVE-2025-54952_CVE-2025-54952

An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to be allocated, potentially r...

Meta Platforms, Inc ExecuTorch CVE
CRITICAL 9.8 CVE-2025-48913

Apache CXF: Untrusted JMS configuration can lead to RCE_CVE-2025-48913

If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially leading to code execution c...

Apache Software Foundation Apache CXF 4.1.0 CVE
CRITICAL 9.8 CVE-2025-53606

Apache Seata (incubating): Deserialization of untrusted Data in Apache Seata Server_CVE-2025-53606

Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubating): 2.4.0. Users are reco...

Apache Software Foundation Apache Seata (incubating) 2.4.0 CVE
CRITICAL 9.8 CVE-2025-52913

CVE-2025-52913_CVE-2025-52913

A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allow an unauthenticated attack...

N/A N/A CVE
CRITICAL 9.8 CVE-2025-5095

Burk Technology ARC Solo Missing Authentication for Critical Function_CVE-2025-5095

Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing an attacker to take over t...

Burk Technology ARC Solo CVE
CRITICAL 9.8 CVE-2025-8284

Packet Power EMX and EG Missing Authentication for Critical Function_CVE-2025-8284

By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulnerability could allow unauth...

Packet Power EMX CVE