Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 CVE-2025-7710

Brave Conversion Engine (PRO) <= 0.7.7 - Authentication Bypass to Administrator_CVE-2025-7710

The Brave Conversion Engine (PRO) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.7.7. This is ...

Brave Brave Conversion Engine (PRO) * CVE
CRITICAL 9.1 CVE-2025-6205

Missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025_CVE-2025-6205

A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to gain privileged acc...

Dassault Systèmes DELMIA Apriso Release 2020 Golden CVE
CRITICAL 9.8 CVE-2025-51536

CVE-2025-51536_CVE-2025-51536

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-36594

CVE-2025-36594_CVE-2025-36594

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2024 release Versi...

Dell PowerProtect Data Domain Feature Release 7.7.1.0 CVE
CRITICAL 9 CVE-2025-44963

CVE-2025-44963_CVE-2025-44963

RUCKUS Network Director (RND) before 4.5 allows spoofing of an administrator JWT by an attacker who knows the hardcoded value of a certain secret key.

RUCKUS Network Director CVE
CRITICAL 9.9 CVE-2025-44961

CVE-2025-44961_CVE-2025-44961

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided by an authenticated user.

RUCKUS SmartZone CVE
CRITICAL 9 CVE-2025-44954

CVE-2025-44954_CVE-2025-44954

RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.

RUCKUS SmartZone CVE
CRITICAL 9.1 CVE-2025-51535

CVE-2025-51535_CVE-2025-51535

Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.

n/a n/a n/a CVE
CRITICAL 9.8 CVE-2025-51390

CVE-2025-51390_CVE-2025-51390

TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter in the setWiFiWpsConfig fu...

n/a n/a n/a CVE
CRITICAL 9.4 CVE-2025-34147

Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via SSID_CVE-2025-34147

An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02). When configuring the...

Shenzhen Aitemi E Commerce Co. Ltd. M300 Wi-Fi Repeater * CVE