CVE-2025-54547Medium· 5.3▾ SunlitOn affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
On affected platforms, if SSH session multiplexing was configured on the client side, SSH sessions (e.g, scp, sftp) multiplexed onto the same channel could perform file-system operations after a configured session timeout expired
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-107275Medium· 6.8@fastify/jwt is a JSON Web Token plugin for the Fastify web framework
CVE-2025-62781Medium· 5.0PILOS (Platform for Interactive Live-Online Seminars) is a frontend for BigBlueButton
CVE-2025-61775NoneVickey is a Misskey-based microblogging platform
CVE-2024-8122Medium· 5.9The WSO2 Identity Server fails to enforce a default expiry time for SMS One-Time Passwords (OTPs) used in multi-factor authentication (MFA)
CVE-2025-53896High· 7.1Kiteworks MFT orchestrates end-to-end file transfer workflows
CVE-2025-36360Medium· 5.0IBM UCD - IBM UrbanCode Deploy 7.1 through 7.1.2.27, 7.2 through 7.2.3.20, and 7.3 through 7.3.2.15 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.10, and 8.1 through 8.1.2.3 is susceptible to a race condition in http-session client-I…