CVE-2025-12509High· 8.4▾ TwilightOn a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
On a client with an admin user, a Global_Shipping script can be implemented. The script could later be executed on the BRAIN2 server with administrator rights.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67900High· 8.1NXLog Agent before 6.11 can load a file specified by the OPENSSL_CONF environment variable.
CVE-2026-105745Medium· 6.7Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem
CVE-2026-105677High· 7.2Ghost is a Node.js content management system
CVE-2026-12171High· 7.8auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source
CVE-2025-39666High· 7.3Local privilege escalation in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0b3 allows a site user to escalate their privileges to root, by manipulating files in th…
CVE-2026-63277High· 8.5LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document