|
Medium
|
11 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8433
|
|
CVE-2025-10573
|
Ivanti Endpoint Manager Cross-Site Scripting (CVE-2025-10573)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8302
|
|
CVE-2025-34392
|
Barracuda Service Center Arbitrary File Write (CVE-2025-34392)
|
|
Critical
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8463
|
|
CVE-2025-11385 CVE-2025-8131 CVE-2025-9791
|
Tenda AC20 Stack Overflow (CVE-2025-11385; CVE-2025-8131; CVE-2025-9791)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2024-3392
|
|
CVE-2024-50631
|
Synology Drive Server SQL Injection (CVE-2024-50631)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8439
|
|
CVE-2025-13486
|
WordPress Advanced Custom Fields Extended Plugin Remote Code Execution (CVE-2025-13486)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8229
|
|
CVE-2025-53417
|
Delta Electronics DIAView Information Disclosure (CVE-2025-53417)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8132
|
|
CVE-2025-14092
|
Edimax BR-6478AC V3 Command Injection (CVE-2025-14092)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8131
|
|
CVE-2025-14106
|
ZSPACE Q2C NAS Command Injection (CVE-2025-14106)
|
|
Critical
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8130
|
|
CVE-2025-14093
|
Edimax BR-6478AC V3 Command Injection (CVE-2025-14093)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8129
|
|
CVE-2025-14108
|
ZSPACE Q2C NAS Command Injection (CVE-2025-14108)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8128
|
|
CVE-2025-14107
|
ZSPACE Q2C NAS Command Injection (CVE-2025-14107)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8127
|
|
CVE-2025-65363
|
Ruijie RG-AP720-L Command Injection (CVE-2025-65363)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8125
|
|
CVE-2025-14225
|
D-Link DCS-930L Command Injection (CVE-2025-14225)
|
|
Medium
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8124
|
|
CVE-2025-65804
|
Tenda AX3 Stack Overflow (CVE-2025-65804)
|
|
Critical
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2024-3344
|
|
CVE-2024-7442 CVE-2024-7443
|
Vivotek Multiple Products Command Injection (CVE-2024-7442; CVE-2024-7443)
|
|
Critical
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2024-3352
|
|
CVE-2024-7441
|
Vivotek SD9364 Buffer Overflow (CVE-2024-7441)
|
|
Critical
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2024-3346
|
|
CVE-2024-35571 CVE-2024-35576 CVE-2024-35578 CVE-2024-35579 CVE-2024-35580 CVE-2024-40414 CVE-2024-40415 CVE-2024-40416 CVE-2024-40417 CVE-2024-4237 CVE-2024-4238 CVE-2024-4239 CVE-2024-44549
|
Tenda AX1806 Buffer Overflow (CVE-2024-35571; CVE-2024-35576; CVE-2024-35578; CVE-2024-35579; CVE-2024-35580; CVE-2024-40414; CVE-2024-40415; CVE-2024-40416; CVE-2024-40417; CVE-2024-4237; CVE-2024-4238; CVE-2024-4239; CVE-2024-44549)
|
|
Critical
|
4 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8319
|
|
CVE-2025-55182
|
React Server Components Remote Code Execution (CVE-2025-55182)
|
|
Critical
|
10 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8486
|
|
CVE-2025-58360
|
GeoServer XML External Entity Injection (CVE-2025-58360)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2022-2952
|
|
CVE-2022-23833
|
Django Denial of Service (CVE-2022-23833)
|
|
Critical
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2024-3354
|
|
CVE-2024-5182
|
Mudler LocalAI Directory Traversal (CVE-2024-5182)
|
|
Medium
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-7032
|
|
CVE-2025-34174
|
pfSense Cross-Site Scripting (CVE-2025-34174)
|
|
Medium
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-7029
|
|
CVE-2025-62411
|
LibreNMS Cross-Site Scripting (CVE-2025-62411)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-7028
|
|
CVE-2025-9872
|
Ivanti Endpoint Manager Remote Code Execution (CVE-2025-9872)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-7027
|
|
CVE-2025-12490
|
Netgate Suricata Directory Traversal (CVE-2025-12490)
|
|
Medium
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2024-2868
|
|
CVE-2024-54779
|
Netgate pfSense Cross-Site Scripting (CVE-2024-54779)
|
|
Medium
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-7023
|
|
CVE-2025-34175
|
pfSense CE Cross-Site Scripting (CVE-2025-34175)
|
|
High
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-7021
|
|
CVE-2025-27240
|
Zabbix SQL Injection (CVE-2025-27240)
|
|
Medium
|
14 Dec 2025 |
14 Dec 2025 |
CPAI-2025-8423
|
|
CVE-2025-24286
|
Veeam Backup and Replication Remote Code Execution (CVE-2025-24286)
|
|
Critical
|
3 Nov 2025 |
14 Dec 2025 |
CPAI-2025-8454
|
|
CVE-2020-25499 CVE-2021-44247 CVE-2024-54907 CVE-2025-4729 CVE-2025-55589 CVE-2025-55590 CVE-2025-55591 CVE-2025-60682
|
TOTOLINK Multiple Products Command Injection (CVE-2020-25499; CVE-2021-44247; CVE-2024-54907; CVE-2025-4729; CVE-2025-55589; CVE-2025-55590; CVE-2025-55591; CVE-2025-60682)
|
|
High
|
18 Sep 2025 |
14 Dec 2025 |
CPAI-2023-2303
|
|
CVE-2023-7308
|
NSFOCUS SecGate3600 Information Disclosure (CVE-2023-7308)
|
|
High
|
1 Sep 2025 |
14 Dec 2025 |
CPAI-2025-0862
|
|
CVE-2025-6970
|
WordPress Events Manager Plugin SQL Injection (CVE-2025-6970)
|
|
High
|
20 Mar 2025 |
14 Dec 2025 |
CPAI-2025-8434
|
|
CVE-2025-0411
|
7-Zip Remote Code Execution (CVE-2025-0411)
|
|
High
|
11 Dec 2025 |
11 Dec 2025 |
CPAI-2025-8328
|
|
CVE-2025-10573
|
Ivanti Endpoint Manager Cross Site Scripting (CVE-2025-10573)
|
|
High
|
11 Dec 2025 |
11 Dec 2025 |
CPAI-2024-3253
|
|
CVE-2024-50629
|
Synology Multiple Products Information Disclosure (CVE-2024-50629)
|
|
Critical
|
11 Dec 2025 |
11 Dec 2025 |
CPAI-2025-7833
|
|
CVE-2025-29268
|
ALLNET ALL-RUT22GW Authentication Bypass (CVE-2025-29268)
|
|
High
|
11 Dec 2025 |
11 Dec 2025 |
CPAI-2025-7591
|
|
CVE-2025-13087
|
Opto22 GRV-EPIC and groov RIO Remote Code Execution (CVE-2025-13087)
|
|
High
|
10 Dec 2025 |
11 Dec 2025 |
CPAI-2025-8329
|
|
CVE-2025-60690 CVE-2025-60691 CVE-2025-60693 CVE-2025-60694
|
Linksys E1200 Buffer Overflow (CVE-2025-60690; CVE-2025-60691; CVE-2025-60693; CVE-2025-60694)
|
|
High
|
11 Dec 2025 |
11 Dec 2025 |
CPAI-2025-7382
|
|
CVE-2025-9482
|
Linksys Multiple Products Stack Overflow (CVE-2025-9482)
|
|
High
|
11 Dec 2025 |
11 Dec 2025 |
CPAI-2025-7955
|
|
CVE-2025-55752
|
Apache Tomcat Directory Traversal (CVE-2025-55752)
|
|
Critical
|
11 Aug 2025 |
11 Dec 2025 |
CPAI-2025-8307
|
|
CVE-2024-34338 CVE-2024-36604 CVE-2025-7414 CVE-2025-7415
|
Tenda O3 Command Injection (CVE-2024-34338; CVE-2024-36604; CVE-2025-7414; CVE-2025-7415)
|
|
High
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7573
|
|
CVE-2025-60694
|
Linksys E1200 Stack Overflow (CVE-2025-60694)
|
|
Critical
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7593
|
|
CVE-2025-58360
|
GeoServer XML External Entity Injection (CVE-2025-58360)
|
|
High
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7690
|
|
CVE-2025-57199
|
AVTECH SECURITY Corporation DGM1104 Command Injection (CVE-2025-57199)
|
|
High
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7689
|
|
CVE-2025-57202
|
AVTECH SECURITY DGM1104 Cross-Site Scripting (CVE-2025-57202)
|
|
High
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7687
|
|
CVE-2025-57200
|
AVTECH SECURITY Corporation DGM1104 Command Injection (CVE-2025-57200)
|
|
High
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7688
|
|
CVE-2025-57198
|
AVTECH SECURITY Corporation DGM1104 Command Injection (CVE-2025-57198)
|
|
Medium
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7632
|
|
CVE-2025-5127
|
Teledyne FLIR AX8 Cross-Site Scripting (CVE-2025-5127)
|
|
High
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7631
|
|
CVE-2025-8078
|
Zyxel ZLD Command Injection (CVE-2025-8078)
|
|
High
|
10 Dec 2025 |
10 Dec 2025 |
CPAI-2025-7629
|
|
CVE-2025-9813
|
Tenda CH22 Buffer Overflow (CVE-2025-9813)
|