CVE-2025-27093Medium· 6.3▾ SunlitSliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Sliver is a command and control framework that uses a custom Wireguard netstack. In versions 1.5.43 and earlier, and in development version 1.6.0-dev, the netstack does not limit traffic between Wireguard clients. This allows clients to communicate with each other unrestrictedly, potentially enabling leaked or recovered keypairs to be used to attack operators or allowing port forwardings to be accessible from other implants.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59218Critical· 9.6Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-11508Medium· 4.7A security vulnerability has been detected in code-projects Voting System 1.0
CVE-2025-11470Medium· 4.7A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0
CVE-2025-11440Medium· 4.3A vulnerability was determined in JhumanJ OpnForm up to 1.9.3
CVE-2025-11436Medium· 6.3A vulnerability was detected in JhumanJ OpnForm up to 1.9.3
CVE-2025-11426Medium· 6.3A security flaw has been discovered in projectworlds Advanced Library Management System 1.0