Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-55613

CVE-2025-55613_CVE-2025-55613

Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.

n/a n/a n/a CVE
CRITICAL 9.8 WALLARMLAB:5238...

Exploiting API4 — 8 Real-World Unrestricted Resource Consumption Attack Scenarios (and How to Stop Them)_WALLARMLAB:52382F1A16D445EE208C3A203404B3B5

**Unrestricted Resource Consumption****(API4:2023)** is the only threat category in the OWASP API Security Top 10 explicitly dedicated to Denial of...

N/A N/A WALLARMLAB
CRITICAL 9.3 CVE-2025-9254

Uniong|WebITR – Missing Authentication_CVE-2025-9254

WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrar...

Uniong WebITR CVE
CRITICAL 10 78E24C22-D356-

Exploit for Improper Authentication in Ivanti Endpoint_Manager_Mobile_78E24C22-D356-5FFD-B0CD-2C2A1A08175D

CVE-2023-35078 Exploit Tool ```bash ██████╗ ███╗ ██╗███████╗███████╗ ██████╗ ██╔═████╗████╗ ██║██╔════╝██╔════╝██╔════╝ ██║██╔██║██╔██╗ ██║█████...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 6B3429BE-F16D-

Exploit for CVE-2024-53900_6B3429BE-F16D-5583-AE95-4C269D9A6F8B

CVE-2024-53900 - Mongoose populate().match \$where RCE This repository provides a reproducible vulnerable...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2025-54988

Apache Tika PDF parser module: XXE vulnerability in PDFParser’s handling of XFA_CVE-2025-54988

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry o...

Apache Software Foundation Apache Tika PDF parser module 1.13 CVE
CRITICAL 9.4 CVE-2025-57761

WeGIA SQL Injection vulnerability via ‘id_funcionario’ param at endpoint `/html/funcionario/dependente_remover.php`_CVE-2025-57761

WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html/funcionario/dependente_rem...

LabRedesCefetRJ WeGIA < 3.4.10 CVE
CRITICAL 9.8 CVE-2025-3128

Mitsubishi Electric Europe smartRTU OS Command Injection_CVE-2025-3128

A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete...

Mitsubishi Electric Europe smartRTU CVE
CRITICAL 9.8 MS:CVE-2025-53763

Azure Databricks Elevation of Privilege Vulnerability_MS:CVE-2025-53763

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE
CRITICAL 9.1 MS:CVE-2025-53795

Microsoft PC Manager Elevation of Privilege Vulnerability_MS:CVE-2025-53795

Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

N/A N/A MSCVE