Latest Vulnerabilities
Latest Found
The latest vulnerability announcements
- CVE-2025-12893 - Improper Certificate Validation May Allow Successful TLS Handshaking Despite Invalid Extended Key Usage Fields in MongoDB Server
- CVE-2025-13507 - Time-series operations may cause internal BSON size limit to be exceed
- CVE-2025-13559 - EduKart Pro <= 1.0.3 - Unauthenticated Privilege Escalation
- CVE-2025-13068 - Telegram Bot & Channel <= 4.1 - Unauthenticated Stored Cross-Site Scripting via Telegram Username
- CVE-2025-13558 - Blog2Social <= 8.7.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Trashing
- CVE-2025-64730 - SNC-CX600W Cross-Site Scripting (XSS) Vulnerability
- CVE-2025-62497 - SNC-CX600W CSRF Vulnerability
- CVE-2025-64304 - FOD App Cryptographic Key Disclosure
- CVE-2025-66182 - Apache HTTP Server SQL Injection
- CVE-2025-66184 - Apache HTTP Server Cross-Site Request Forgery
CISA Advisories
The latest advisories from CISA
- Spyware Allows Cyber Threat Actors to Target Users of Messaging Applications
- CISA Adds One Known Exploited Vulnerability to Catalog
- Festo MSE6-C2M/D2M/E2M
- Automated Logic WebCTRL Premium Server
- Emerson Appleton UPSMON-PRO
- CISA Releases Six Industrial Control Systems Advisories
- ICAM365 CCTV Camera Multiple Models
- Opto 22 GRV-EPIC and groov RIO
- Festo Didactic products
- CISA Adds One Known Exploited Vulnerability to Catalog