|
cve-2025-54068
|
Laravel Livewire Code Injection Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2026-03-20 |
|
cve-2025-5394
|
Alone – Charity Multipurpose Non-profit WordPress Theme <= 7.8.3 - Missing Authorization to Unauthenticated Arbitrary File Upload via Plugin Installation |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2025-53770
|
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2025-07-20 |
|
cve-2025-53690
|
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability |
CRITICAL
|
9.0
|
N/A
|
cvelistv5 |
2025-09-04 |
|
cve-2025-53521
|
F5 BIG-IP Stack-Based Buffer Overflow Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2026-03-27 |
|
cve-2025-53364
|
CVE-2025-53364 |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
|
|
cve-2025-53118
|
Securden Unified PAM Authentication Bypass |
CRITICAL
|
9.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2025-52907
|
CVE-2025-52907 |
HIGH
|
7.3
|
N/A
|
cvelistv5 |
|
|
cve-2025-5287
|
CVE-2025-5287 |
HIGH
|
7.5
|
N/A
|
cvelistv5 |
|
|
cve-2025-52691
|
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability |
CRITICAL
|
10.0
|
N/A
|
cvelistv5 |
2026-01-26 |
|
cve-2025-52488
|
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input |
HIGH
|
8.6
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2025-51482
|
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, bypassing intended sandbox restrictions. |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2025-5086
|
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2025-09-11 |
|
cve-2025-49706
|
Microsoft SharePoint Improper Authentication Vulnerability |
CRITICAL
|
N/A
|
N/A
|
cvelistv5 |
2025-07-22 |
|
cve-2025-49704
|
Microsoft SharePoint Code Injection Vulnerability |
HIGH
|
8.8
|
N/A
|
cvelistv5 |
2025-07-22 |
|
cve-2025-49533
|
CVE-2025-49533 |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
|
|
cve-2025-49493
|
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. |
MEDIUM
|
5.8
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2025-49113
|
RoundCube Webmail Deserialization of Untrusted Data Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2026-02-20 |
|
cve-2025-48928
|
TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability |
MEDIUM
|
4.0
|
N/A
|
cvelistv5 |
2025-07-01 |
|
cve-2025-48927
|
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability |
MEDIUM
|
5.3
|
N/A
|
cvelistv5 |
2025-07-01 |
|
cve-2025-48828
|
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine. By crafting template code in an alternative PHP function invocation syntax, such as the "var_dump"("test") syntax, attackers can bypass security checks and execute arbitrary PHP code, as exploited in the wild in May 2025. |
CRITICAL
|
9.0
|
N/A
|
cvelistv5 |
2026-06-17 |
|
cve-2025-48827
|
CVE-2025-48827 |
CRITICAL
|
10.0
|
N/A
|
cvelistv5 |
|
|
cve-2025-48703
|
CWP Control Web Panel OS Command Injection Vulnerability |
CRITICAL
|
9.0
|
N/A
|
cvelistv5 |
2025-11-04 |
|
cve-2025-48700
|
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2026-04-20 |
|
cve-2025-48633
|
Android Framework Information Disclosure Vulnerability |
MEDIUM
|
5.5
|
N/A
|
cvelistv5 |
2025-12-02 |
|
cve-2025-48572
|
Android Framework Privilege Escalation Vulnerability |
HIGH
|
7.8
|
N/A
|
cvelistv5 |
2025-12-02 |
|
cve-2025-48543
|
Android Runtime Use-After-Free Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2025-09-04 |
|
cve-2025-48384
|
Git Link Following Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2025-08-25 |
|
cve-2025-47916
|
CVE-2025-47916 |
CRITICAL
|
10.0
|
N/A
|
cvelistv5 |
|
|
cve-2025-47827
|
IGEL OS Use of a Key Past its Expiration Date Vulnerability |
HIGH
|
N/A
|
N/A
|
cvelistv5 |
2025-10-14 |