Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2025-5048

DGN File Parsing Memory Corruption Vulnerability_CVE-2025-5048

A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerability. A malicious actor can l...

Autodesk AutoCAD 2026 CVE
HIGH 7.2 CVE-2025-1929

SQLi in RiskTurk’s Treasury Management Software_CVE-2025-1929

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sek...

Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı CVE
HIGH 8.5 CVE-2025-54474

Extension – dj-extensions.com – SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla_CVE-2025-54474

A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged users to execute arbitrary SQL...

dj-extensions.com DJ-Classifieds component for Joomla 3.9.2-3.10.1 CVE
HIGH 8.7 CVE-2025-54475

Extension – joomsky.com – SQL injection in JS jobs component version 1.3.2 – 1.4.4 for Joomla_CVE-2025-54475

A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execute arbitrary SQL commands.

joomsky.com JS Jobs component for Joomla 1.3.2-1.4.4 CVE
HIGH 8.7 CVE-2025-9046

Tenda AC20 setMacFilterCfg sub_46A2AC stack-based overflow_CVE-2025-9046

A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform/setMacFilterCfg. The manip...

Tenda AC20 16.03.08.12 CVE
HIGH 8.7 CVE-2025-9023

Tenda AC7/AC18 SetLEDCfg formSetSchedLed buffer overflow_CVE-2025-9023

A vulnerability has been found in Tenda AC7 and AC18 15.03.05.19/15.03.06.44. Affected is the function formSetSchedLed of the file /goform/SetLEDCf...

Tenda AC7 15.03.05.19 CVE
HIGH 7.5 CVE-2025-7650

BizCalendar Web <= 1.1.0.50 - Authenticated (Contributor+) Local File Inclusion_CVE-2025-7650

The BizCalendar Web plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.0.50 via the 'bizcalv' sho...

setriosoft BizCalendar Web * CVE
HIGH 7.5 CVE-2025-7641

Assistant for NextGEN Gallery <= 1.0.9 - Unauthenticated Arbitrary Directory Deletion_CVE-2025-7641

The Assistant for NextGEN Gallery plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation in th...

48hmorris Assistant for NextGEN Gallery * CVE
HIGH 7.3 CVE-2025-9016

Mechrevo Control Center GX V2 Powershell Script Command uncontrolled search path_CVE-2025-9016

A vulnerability was identified in Mechrevo Control Center GX V2 5.56.51.48. This affects an unknown part of the file C:\Program Files\OEM\机械革命...

Mechrevo Control Center GX V2 5.56.51.48 CVE
HIGH 8.7 CVE-2025-9007

Tenda CH22 editFileName formeditFileName buffer overflow_CVE-2025-9007

A vulnerability has been found in Tenda CH22 1.0.0.1. Affected by this issue is the function formeditFileName of the file /goform/editFileName. The...

Tenda CH22 1.0.0.1 CVE