Miggo Predictive Vulnerability Database
Comprehensive vulnerability intelligence for security teams to gain clarity into CVEs to prioritize and respond with precision.
Concerned about an active attack path? Talk to our security experts and see Miggo in action
Contact UsTop 10 CVEs
New vulnerabilities last 30 days
CVE-2025-62519: phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
phpMyFAQ authenticated SQLi in configuration updates grants privileged users arbitrary SQL execution via unsanitized form keys injected into raw UPDATE queries.
Analysis:
Available
7.2
high
11/17/2025
CVE-2025-13261: lsFusion Platform has Path Traversal vulnerability
lsFusion Platform path traversal in DownloadFileRequestHandler via Version argument manipulation grants remote attackers arbitrary file system read access.
Analysis:
Available
5.3
medium
11/17/2025
CVE-2025-55449: AstrBot is vulnerable to RCE with hard-coded JWT signing keys
AstrBot RCE via hard-coded JWT signing key grants attackers auth bypass to install malicious Python plugins for arbitrary command execution on the host.
Analysis:
Available
9.8
critical
11/14/2025
GHSA-m8jr-fxqx-8xx6: Apollo Federation has Improper Enforcement of Access Control on Transitive Fields
Apollo Federation authorization bypass grants access to protected data by querying fields with @requires or @fromContext that bypass transitive field policies.
Analysis:
Available
7.5
high
11/14/2025