CVE-2025-59468Critical· 9.0▾ MidnightThis vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 49.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.2%
This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.
veeam_backup_&_replication >= 13.0.0.4967, < 13.0.1.1071Upgrade past the affected range:
veeam_backup_&_replication 13.0.1.1071Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59470Critical· 9.0This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.
CVE-2025-55125High· 7.8This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.
CVE-2025-59469Critical· 9.0This vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2025-11523Medium· 6.3A vulnerability was detected in Tenda AC7 15.03.06.44
CVE-2025-59834Critical· 9.8ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0