Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 10 5F5FBE6A-B142-

Exploit for Missing Authentication for Critical Function in Erlang Erlang\/Otp_5F5FBE6A-B142-52F1-8775-963253AA056A

CVE-2025-32433 – Erlang/OTP SSH RCE Vulnerability 📌 Summary CVE-2025-32433 is a remote...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2025-55583

CVE-2025-55583_CVE-2025-55583

D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in the fileaccess.cgi compone...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-48100

WordPress bidorbuy Store Integrator plugin <= 2.12.0 - Remote Code Execution (RCE) vulnerability_CVE-2025-48100

Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator allows Remote Code Inclusion. This...

extremeidea bidorbuy Store Integrator n/a CVE
CRITICAL 10 CVE-2025-49387

WordPress Drag and Drop File Upload for Elementor Forms Plugin <= 1.5.3 - Arbitrary File Upload Vulnerability_CVE-2025-49387

Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms allows Upload a Web Shel...

add-ons.org Drag and Drop File Upload for Elementor Forms n/a CVE
CRITICAL 9.8 CVE-2025-49388

WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability_CVE-2025-49388

Incorrect Privilege Assignment vulnerability in kamleshyadav Miraculous Core Plugin allows Privilege Escalation. This issue affects Miraculous Core...

kamleshyadav Miraculous Core Plugin n/a CVE
CRITICAL 9.8 CVE-2025-52761

WordPress WP Funnel Manager Plugin <= 1.4.0 - PHP Object Injection Vulnerability_CVE-2025-52761

Deserialization of Untrusted Data vulnerability in manfcarlo WP Funnel Manager allows Object Injection. This issue affects WP Funnel Manager: from ...

manfcarlo WP Funnel Manager n/a CVE
CRITICAL 9.3 CVE-2025-54720

WordPress Nest Addons Plugin <= 1.6.3 - SQL Injection Vulnerability_CVE-2025-54720

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons allows SQL Injection....

SteelThemes Nest Addons n/a CVE
CRITICAL 9.8 CVE-2025-54725

WordPress Golo Theme <= 1.7.0 - Broken Authentication Vulnerability_CVE-2025-54725

Authentication Bypass Using an Alternate Path or Channel vulnerability in uxper Golo allows Authentication Abuse. This issue affects Golo: from n/a...

uxper Golo n/a CVE
CRITICAL 9.8 CVE-2025-54738

WordPress Jobmonster Theme <= 4.7.9 - Broken Authentication Vulnerability_CVE-2025-54738

Authentication Bypass Using an Alternate Path or Channel vulnerability in NooTheme Jobmonster allows Authentication Abuse. This issue affects Jobmo...

NooTheme Jobmonster n/a CVE
CRITICAL 9.8 EDF9DFFD-577C-

Exploit for CVE-2025-7955_EDF9DFFD-577C-5E0F-A454-256B8522C303

CVE-2025-7955 RingCentral...

N/A N/A GITHUBEXPLOIT