CVE-2025-45480Low· 3.0▾ SunlitFloodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 16.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92952Medium· 6.8vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary
CVE-2026-20194Critical· 9.1As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…
CVE-2026-38924Low· 2.9In Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0
CVE-2023-37252Low· 3.1An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3
CVE-2026-25832Low· 3.7In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.
CVE-2023-37253Low· 3.1An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3