| Title | CVE ID | Author | Credit | Severity | Post Date | Action |
|---|---|---|---|---|---|---|
| Vvveb - v1.0.5 - Cross-Site Scripting via SVG | CVE-2025-8976 | 0xhamy | High | 2025-10-22 | ||
| Vvveb - v1.0.5 - Cross-Site Scripting via navbar | CVE-2025-8521 | 0xhamy | High | 2025-10-22 | ||
| EasyAppointments - v1.5.0 - Password Brute Force | CVE-2024-57602 | 0xhamy | Critical | 2025-10-22 | ||
| EasyAppointments - v1.5.0 - Cross-Site Scripting | CVE-2024-57601 | 0xhamy | High | 2025-10-22 | ||
| OnlyOffice Community Server - v12.7.0 - Cross-Site Scripting (cross-origin) | CVE-2025-10255 | 0xhamy,daeda1us | Low | 2025-10-22 | ||
| OnlyOffice Community Server - v12.7.0 - Cross-Site Scripting | CVE-2025-10254 | 0xhamy,daeda1us | High | 2025-10-22 | ||
| Lemon OS - vnightly-2024-07-12 - Remote stack overflow | CVE-2025-9001 | 0xhamy | High | 2025-10-22 | ||
| Apache Answer - v1.4.1 - Externally referenced images can leak user privacy | CVE-2025-29868 | 0xhamy,daeda1us | Medium | 2025-10-22 | ||
| Mentingo - File Upload to XSS | CVE-2025-10741 | KhanMarshai | Medium | 2025-10-16 | ||
| Frappe LMS - v2.35.0 - Improper Access Controls | CVE-2025-11281 | 0xhamy,KhanMarshai | Medium | 2025-10-14 | ||
| Frappe LMS - v2.35.0 - Improper Access Controls (unauthenticated) | CVE-2025-11280 | 0xhamy,KhanMarshai | High | 2025-10-14 | ||
| Frappe LMS - v2.35.0 - Cross-Site Scripting as student | CVE-2025-11282 | 0xhamy,KhanMarshai | High | 2025-10-14 | ||
| Frappe LMS - v2.35.0 - Cross-Site Scripting as instructor | CVE-2025-11283 | 0xhamy,KhanMarshai | Medium | 2025-10-14 | ||
| Typo3 CMS - v13.4.11 - Unrestricted File Upload | CVE-2025-47939 | 0xhamy | Medium | 2025-09-29 | ||
| NukeViet - v4.5.06 - Server Side Request Forgery | CVE-2025-8772 | 0xhamy | High | 2025-09-29 | ||
| Vvveb - v1.0.5 - Code Execution | CVE-2025-8518 | 0xhamy | Critical | 2025-09-29 | ||
| Vvveb - v1.0.5 - Server Side Request Forgery | CVE-2025-8520 | 0xhamy | Medium | 2025-09-29 | ||
| Vvveb - v1.0.5 - Internal File Read | CVE-2025-8519 | 0xhamy | Medium | 2025-09-29 | ||
| Fuel CMS - v1.5.2 - Cross-Site Scripting | CVE-2024-57605 | 0xhamy | High | 2025-09-29 | ||
| ezBookkeeping - v0.7.0 - Login Bruteforce | CVE-2024-57603 | 0xhamy | Critical | 2025-09-29 |