CVE-2025-59461High· 7.6▾ TwilightA remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
tloc100-100_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59462Medium· 6.5An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.
CVE-2025-59463Medium· 4.3An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.
CVE-2025-59459Medium· 5.5An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.
CVE-2025-12924Medium· 4.3A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224
CVE-2024-0829Medium· 4.3The Comments Extra Fields For Post,Pages and CPT plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.0
CVE-2025-13772High· 7.1GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorize…