Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-8454

CVE-2025-8454_CVE-2025-8454

It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts t...

Debian devscripts CVE
CRITICAL 9.8 CVE-2025-50460

CVE-2025-50460_CVE-2025-50460

A remote code execution (RCE) vulnerability exists in the ms-swift project version 3.3.0 due to unsafe deserialization in tests/run.py using yaml.l...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-52390

CVE-2025-52390_CVE-2025-52390

Saurus CMS Community Edition since commit d886e5b0 (2010-04-23) is vulnerable to a SQL Injection vulnerability in the `prepareSearchQuery()` method...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-50472

CVE-2025-50472_CVE-2025-50472

The modelscope/ms-swift library thru 2.6.1 is vulnerable to arbitrary code execution through deserialization of untrusted data within the `load_mod...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-45150

CVE-2025-45150_CVE-2025-45150

Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a craf...

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-50870

CVE-2025-50870_CVE-2025-50870

Institute-of-Current-Students 1.0 is vulnerable to Incorrect Access Control in the mydetailsstudent.php endpoint. The myds GET parameter accepts an...

n/a n/a n/a CVE
CRITICAL 9.1 CVE-2025-6000

Arbitrary Remote Code Execution via Plugin Catalog Abuse_CVE-2025-6000

A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a ...

HashiCorp Vault 0.8.0 CVE
CRITICAL 9.3 CVE-2025-54574

Squid’s URN Handling can lead to Buffer Overflow_CVE-2025-54574

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution a...

squid-cache squid < 6.4 CVE
CRITICAL 9.3 CVE-2025-54792

LocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File Interception_CVE-2025-54792

LocalSend is an open-source app to securely share files and messages with nearby devices over local networks without needing an internet connection...

localsend localsend <= 1.17.0 CVE
CRITICAL 9.2 CVE-2025-54790

Files: Potential for SQL Injection through File Browse and List Operations_CVE-2025-54790

Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploi...

humhub cfiles < 0.16.10 CVE