CVE-2025-36890 – Apache Struts Command Execution

Affected Products The following products are affected by CVE-2025-36890 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-36902 – Syna TCM2 Heap Buffer Overflow Vulnerability

Affected Products The following products are affected by CVE-2025-36902 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-36903 – Lwis Buffer Write OOB Read/Write Vulnerability

Affected Products The following products are affected by CVE-2025-36903 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-9517 – Atlassian Confluence Debug Plugin Remote Code Execution Vulnerability

The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 via the ‘custom_log’ parameter. This is due to insufficient sanitization when saving the custom log path. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

CVE-2025-36894 – Apache TBD HTTP Denial of Service

Affected Products The following products are affected by CVE-2025-36894 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet

CVE-2025-36901 – Apache Struts Remote Code Execution

Affected Products The following products are affected by CVE-2025-36901 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below. No affected product recoded yet