Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.9 CVE-2025-53251

WordPress Pin WP theme <= 6.9 - Arbitrary File Upload Vulnerability_CVE-2025-53251

Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP allows Upload a Web Shell to a Web Server.This issue affects Pin ...

An-Themes Pin WP n/a CVE
CRITICAL 9.8 CVE-2025-27214

CVE-2025-27214_CVE-2025-27214

A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjac...

Ubiquiti Inc UniFi Connect EV Station Pro 1.5.27 CVE
CRITICAL 9.1 CVE-2025-27217

CVE-2025-27217_CVE-2025-27217

A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP ...

Ubiquiti Inc UISP Application 2.4.220 CVE
CRITICAL 9.8 CVE-2025-24285

CVE-2025-24285_CVE-2025-24285

Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network...

Ubiquiti Inc UniFi Connect EV Station Lite 1.5.2 CVE
CRITICAL 10 CVE-2025-34158

Plex Media Server (PMS) 1.41.7.x – 1.42.0.x Unspecified Vulnerabiliity_CVE-2025-34158

Plex Media Server (PMS) versions 1.41.7.x through 1.42.0.x are affected by an unspecified security vulnerability reported via Plex’s bug bounty pro...

Plex, Inc. Plex Media Server 1.41.7.x CVE
CRITICAL 9.8 CVE-2025-50904

CVE-2025-50904_CVE-2025-50904

There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-55444

CVE-2025-55444_CVE-2025-55444

A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote ...

n/a n/a n/a CVE
CRITICAL 9.8 7B41EE7B-2748-

Exploit for Incorrect Authorization in Apache Shiro_7B41EE7B-2748-5521-8823-01E419A5730A

Apache Shiro CVE-2022-32532 复现环境 这是一个用于复现 CVE-2022-32532(Apache Shiro RegExPatternMatcher 认证绕过)的最小化 Web 应用。...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 7D5B07AF-EAEE-

Exploit for Code Injection in Craftcms Craft_Cms_7D5B07AF-EAEE-5814-B0D1-79478A43DC2A

CVE-2023-41892_poc Customized this for my own use poc_noauth.py 기본 PHP 원라인 웹쉘 ?cmd= 통한 OS 명령어 실행 poc_auth.py 간단한 키 기반 인증이...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 CVE-2025-8895

WP Webhooks <= 3.3.5 - Unauthenticated Arbitrary File Copy_CVE-2025-8895

The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, a...

cozmoslabs WP Webhooks – Automate repetitive tasks by creating powerful automation workflows directly within WordPress * CVE