As part of our ongoing research and consulting efforts, we frequently discover vulnerabilities in third-party products. Committed to enhancing the security of the digital ecosystem, we publish detailed security advisories according our vulnerability disclosure policy. You can find the full security advisories with complete details in our Github repository.
Below is an overview of our latest security advisories:
-
Filebrowser Command Execution not Limited to Scope (CVE-2025-52904)
-
Filebrowser Shell Commands Can Spawn Other Commands (CVE-2025-52903)
-
Filebrowser Stored Cross-Site Scripting (CVE-2025-52902)
-
Filebrowser Sensitive Data Transferred in URL (CVE-2025-52901)
-
Filebrowser Insecure File Permissions (CVE-2025-52900)
-
Cyberduck and Mountain Duck – Weak Hash Algorithm for Certificate Fingerprint (CVE-2025-41256)
-
Cyberduck and Mountain Duck – Improper Certificate Store Handling (CVE-2025-41255)
-
Null pointer dereference in MediaTek Modem (CVE-2025-20647)