Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-43237

CVE-2025-43237_CVE-2025-43237

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause un...

Apple macOS unspecified CVE
CRITICAL 9.8 CVE-2025-43233

CVE-2025-43233_CVE-2025-43233

This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A...

Apple macOS unspecified CVE
CRITICAL 9.8 CVE-2025-46811

SUSE Multi Linux Manager has unprotected websocket endpoint_CVE-2025-46811

A Missing Authentication for Critical Function vulnerability in SUSE Manager allows anyone with access to the websocket at /rhn/websocket/minion/re...

SUSE Container suse/manager/5.0/x86_64/server:5.0.5.7.30.1 ? CVE
CRITICAL 9.1 CVE-2025-54576

OAuth2-Proxy has authentication bypass in oauth2-proxy skip_auth_routes due to Query Parameter inclusion_CVE-2025-54576

OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse pr...

oauth2-proxy oauth2-proxy < 7.11.0 CVE
CRITICAL 9.8 CVE-2025-50475

CVE-2025-50475_CVE-2025-50475

An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitra...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-26063

CVE-2025-26063_CVE-2025-26063

An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload i...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-26062

CVE-2025-26062_CVE-2025-26062

An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obt...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-8286

Güralp Systems Güralp FMUS series Missing Authentication for Critical Function_CVE-2025-8286

Güralp FMUS series seismic monitoring devices expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify...

Güralp Systems Güralp FMUS Series Seismic Monitoring Devices All versions CVE
CRITICAL 9.8 CVE-2025-5954

Service Finder SMS System <= 2.0.0 - Unauthenticated Privilege Escalation_CVE-2025-5954

The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including,...

aonetheme Service Finder SMS System * CVE
CRITICAL 9.8 CVE-2025-5947

Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie_CVE-2025-5947

The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all versions up to, and includi...

aonetheme Service Finder Bookings * CVE