tag
Cloud
CVE-2025-55182
web
CRITICAL 10
KEV
Ransomware
EPSS 100%
React2Shell - Next.js RSC Unauthenticated RCE
CVE-2025-55182 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Next.js applications using React Server Components (RSC) with the App Router. The exploit abuses unsafe deserialization of the RSC wire format: a crafted multipart POST…
Patched
2026-05-17
CVE-2025-54914
cloud
CRITICAL 10
Azure Networking Privilege Escalation via Missing Privilege Check
CVE-2025-54914 is a critical privilege escalation vulnerability (CVSS 10.0) in Microsoft Azure Networking. Discovered by Mark Mallia and disclosed on September 4, 2025, the flaw arises from a missing authorization check in the GetRouteTable API code path. A…
Patched
2026-05-17