Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.9 CVE-2025-54426

Polkadot Frontier contains silent failure in Curve25519 arithmetic precompiles with malformed points_CVE-2025-54426

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f70d1, the Curve25519Add and...

polkadot-evm frontier < 36f70d1 CVE
CRITICAL 9.8 CVE-2025-54428

RevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)_CVE-2025-54428

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions bel...

musombi123 RevelaCode-Backend < 1.0.1 CVE
CRITICAL 9 CVE-2025-8264

CVE-2025-8264_CVE-2025-8264

Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in the IMAP backend. An attac...

n/a z-push/z-push-dev CVE
CRITICAL 9.8 CVE-2025-50738

CVE-2025-50738_CVE-2025-50738

The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a user views a memo containing ...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-44136

CVE-2025-44136_CVE-2025-44136

MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an error message without html e...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-40600

CVE-2025-40600_CVE-2025-40600

Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticated attacker to cause service...

SonicWall SonicOS 7.2.0-7015 and older versions CVE
CRITICAL 9.9 CVE-2025-54381

BentoML is Vulnerable to an SSRF Attack Through File Upload Processing_CVE-2025-54381

BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.0 until 1.4.19, the file...

bentoml BentoML >= 1.4.0, < 1.4.19 CVE
CRITICAL 9.8 28A0E7E7-B7A9-

Exploit for Code Injection in Xwiki_28A0E7E7-B7A9-51E8-BD5F-02A9A7D84B3A

CVE-2025-24893 - XWiki Unauthenticated Remote Code Execution...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.8 FA0C9DD6-DE32-

Exploit for Improper Restriction of XML External Entity Reference in Adobe Commerce_FA0C9DD6-DE32-5E4E-A70B-4E1977F06B95

Cosmic Sting: CVE-2024-34102 Exploiter Cosmic Sting is...

N/A N/A GITHUBEXPLOIT
CRITICAL 9.1 CVE-2025-43273

CVE-2025-43273_CVE-2025-43273

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able ...

Apple macOS unspecified CVE