Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.4 CVE-2025-54299

Extension – nobossextensions.com – Stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla_CVE-2025-54299

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

nobossextensions.com No Boss Testimonials component for Joomla 4.0.0-4.0.2 CVE
CRITICAL 9.4 CVE-2025-54298

Extension – firecoders.com – Stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla_CVE-2025-54298

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

firecoders.com CommentBox component for Joomla 1.0.0-1.1.0 CVE
CRITICAL 10 CVE-2025-54419

Node-SAML Contains SAML Signature Verification Vulnerability_CVE-2025-54419

A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original resp...

node-saml node-saml = 5.0.1 CVE
CRITICAL 9.9 CVE-2025-54426

Polkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed points_CVE-2025-54426

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and...

polkadot-evm frontier < 36f70d1 CVE
CRITICAL 9.8 CVE-2025-54428

RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)_CVE-2025-54428

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions bel...

musombi123 RevelaCode-Backend < 1.0.1 CVE
CRITICAL 9 CVE-2025-8264

CVE-2025-8264_CVE-2025-8264

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attac...

n/a z-push/z-push-dev CVE
CRITICAL 9.8 CVE-2025-50738

CVE-2025-50738_CVE-2025-50738

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing ...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-44136

CVE-2025-44136_CVE-2025-44136

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html e...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-40600

CVE-2025-40600_CVE-2025-40600

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service...

SonicWall SonicOS 7.2.0-7015 and older versions CVE
CRITICAL 9.9 CVE-2025-54381

BentoML is Vulnerable to an SSRF Attack Through File Upload Processing_CVE-2025-54381

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file...

bentoml BentoML >= 1.4.0, < 1.4.19 CVE