Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
GHSA-f74j-gffq-vm9p: pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer
pyquokka FlightServer RCE via unsafe pickle deserialization in the do_action method grants remote attackers arbitrary code execution via malicious payloads.
Analysis:
Available
9.8
critical
10/17/2025
CVE-2025-48044: Ash has authorization bypass when bypass policy condition evaluates to true
Ash authorization bypass grants unauthorized resource access when a bypass policy condition is true but its authorization checks fail during policy evaluation.
Analysis:
Available
8.1
high
10/17/2025
CVE-2025-62505: Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
Lobe Chat SSRF in the tools.search.crawlPages tRPC endpoint lets attackers force the naive web fetch implementation to access internal networks and metadata.
Analysis:
Available
3
low
10/17/2025
CVE-2025-10044: Keycloak error_description injection on error pages that can trigger phishing attacks
Keycloak account console content injection via the error_description query param displays arbitrary text in the UI, creating a vector for phishing attacks.
Analysis:
Available
4.3
medium
10/17/2025