Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2025-5039

Privilege Ecalation due to Untrusted Search Path Vulnerability_CVE-2025-5039

A maliciously crafted binary file, when present while loading files in certain Autodesk applications, could lead to execution of arbitrary code in ...

Autodesk RealDWG 2026 CVE
HIGH 8.7 CVE-2025-6998

Calibre Web 0.6.24 & Autocaliweb 0.7.0 – ReDoS_CVE-2025-6998

ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denia...

Calibre Web Calibre Web 0.6.24 CVE
HIGH 7.1 CVE-2025-31953

HCL iAutomate is affected by hardcoded credentials_CVE-2025-31953

HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized...

HCL Software iAutomate 6.5.1 CVE
HIGH 7.6 CVE-2025-31955

HCL iAutomate is affected by a sensitive data exposure vulnerability_CVE-2025-31955

HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the...

HCL Software iAutomate 6.5.1 CVE
HIGH 7.1 CVE-2025-31952

HCL iAutomate is affected by an insufficient session expiration_CVE-2025-31952

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasi...

HCL Software iAutomate 6.5.1 CVE
HIGH 8.9 CVE-2025-54379

eKuiper API endpoints handling SQL queries with user-controlled table names._CVE-2025-54379

LF Edge eKuiper is a lightweight IoT data analytics and stream processing engine running on resource-constraint edge devices. In versions before 2....

lf-edge ekuiper < 2.2.1 CVE
HIGH 8.5 CVE-2025-53940

Quiet uses insecure, inconsistent verification on local backend token_CVE-2025-53940

Quiet is an alternative to team chat apps like Slack, Discord, and Element that does not require trusting a central server or running one's own. In...

TryQuiet quiet < 6.0.1 CVE
HIGH 8.3 CVE-2025-7742

Authentication Bypass in LG Innotek Camera_CVE-2025-7742

An authentication vulnerability exists in the LG Innotek camera model LNV5110R firmware that allows a malicious actor to upload an HTTP POST reques...

LG Innotek Camera Model LNV5110R All CVE
HIGH 8.7 CVE-2025-8131

Tenda AC20 SetStaticRouteCfg stack-based overflow_CVE-2025-8131

A vulnerability was found in Tenda AC20 16.03.08.05. It has been declared as critical. Affected by this vulnerability is an unknown functionality o...

Tenda AC20 16.03.08.05 CVE
HIGH 8.8 CVE-2025-5835

Droip <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Many Actions_CVE-2025-5835

The Droip plugin for WordPress is vulnerable to unauthorized modification and access of data due to a missing capability check on the droip_post_ap...

Droip Droip * CVE