CVE-2021-39935
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's vulnerability disclosures reveal significant exposure across Microsoft Windows and Office products, with multiple actively exploited flaws targeting core enterprise infrastructure. The brief includes 1 critical vulnerability (down 50% from prior day) and 63 high-priority CVEs (down 37%), reflecting a quieter but still consequential disclosure cycle. CVE-2026-24494 (CVSS 9.8) affects the Online Ordering System, while five Microsoft Windows CVEs and one Office CVE are confirmed under active exploitation. Notably, legacy vulnerabilities in GitLab, Zimbra, Roundcube Webmail, and Sangoma FreePBX continue to see exploitation activity, underscoring persistent risk from unpatched older systems. Patch availability stands at 0%, making compensating controls and network-level mitigations essential until vendor fixes are released.
Immediate action: Prioritize reviewing exposure to Microsoft Windows, Office, Roundcube Webmail, and GitLab environments, as these face confirmed active exploitation with no patches currently available. Implement network segmentation, access restrictions, and enhanced monitoring for affected systems as compensating controls until vendor patches are released.
GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX OS Command Injection Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX Improper Authentication Vulnerability - Active in CISA KEV catalog.
React Native Community CLI OS Command Injection Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
A protection mechanism failure in the MSHTML Framework allows an unauthenticated attacker to bypass security features over a network, potentially leading to unauthorized system access.
Microsoft Windows NULL Pointer Dereference Vulnerability - Active in CISA KEV catalog.
A protection mechanism failure in the Windows Shell allows an unauthenticated attacker to bypass security features over a network connection.
Improper privilege management in Windows Remote Desktop allows an authorized attacker to elevate their privileges locally on the affected system.
A type confusion vulnerability in the Desktop Window Manager (DWM) allows an authorized local attacker to elevate their privileges to a higher level.
A security feature bypass vulnerability in Microsoft Office Word exists due to reliance on untrusted inputs, allowing an unauthorized local attacker to circumvent security protections.
A memory corruption vulnerability in Apple software was addressed through improved state management to prevent potential exploitation.
Microsoft Configuration Manager SQL Injection Vulnerability - Active in CISA KEV catalog.
Notepad++ Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Google Chrome is vulnerable to a "Use After Free" condition in its CSS engine, which could allow a remote attacker to execute arbitrary code via a crafted webpage.
GitLab Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
RoundCube Webmail Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
An unauthenticated SQL injection vulnerability exists in the Order Up Online Ordering System 1.0 via the store_id parameter in the /api/integrations/getintegrations endpoint.
Ashop Shopping Cart Software contains a time-based blind SQL injection vulnerability that allows attackers to manipulate database queries through the blacklistitemid parameter
WebIncorp ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the prod_id parameter
Inventory Webapp contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters
DIGIT CENTRIS ERP contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the datum1, datum2, KID, and PID parameters
Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter
Web Ofisi E-Ticaret v3 contains an unauthenticated SQL injection vulnerability in the 'a' parameter, allowing for unauthorized database manipulation.
Web Ofisi Emlak v2 is vulnerable to an unauthenticated SQL injection via the 'ara' GET parameter, enabling attackers to manipulate database queries.
Web Ofisi Firma v13 contains an unauthenticated SQL injection vulnerability via the 'oz' array parameter, allowing for the manipulation of backend database queries.
Web Ofisi Firma Rehberi v1 is vulnerable to an unauthenticated SQL injection through various GET parameters, allowing attackers to manipulate database queries.
Web Ofisi Emlak V2 contains multiple SQL injection vulnerabilities in its endpoints, allowing unauthenticated attackers to manipulate database queries via GET parameters.
Web Ofisi Platinum E-Ticaret v5 is vulnerable to an unauthenticated SQL injection via the 'q' GET parameter, allowing for unauthorized database manipulation.
Web Ofisi Rent a Car v3 contains an unauthenticated SQL injection vulnerability in the 'klima' parameter, allowing attackers to execute arbitrary SQL commands.
XOOPS CMS 2
Dolibarr ERP/CRM 10
A weakness has been identified in funadmin up to 7
A security flaw has been discovered in Tosei Online Store Management System ãããåēčįŽĄįãˇãšãã 1
A flaw has been found in Vaelsys 4
Dolibarr ERP/CRM 10
A high-severity vulnerability has been identified in itsourcecode Vehicle Management System 1, though specific technical details of the flaw are currently limited.
A security vulnerability has been identified in code-projects Online Reviewer System 1, which could allow an attacker to compromise the integrity and confidentiality of the application data.
A vulnerability has been identified in SourceCodester Student Result Management System 1, potentially allowing for unauthorized data access or system manipulation.
Zohocorp ManageEngine ADSelfService Plus versions 6522 and below are vulnerable to authenticated SQL Injection in the search report option
NoviSmart CMS is vulnerable to a high-severity SQL injection via the Referer HTTP header, allowing remote attackers to execute arbitrary SQL queries against the database.
A security flaw has been discovered in Tenda A21 1
A weakness has been identified in Tenda A21 1
A security vulnerability has been detected in Tenda A21 1
A vulnerability was detected in Tenda A21 1
A flaw has been found in Tenda A21 1
A vulnerability was determined in Tenda A18 15
A vulnerability has been found in Tenda A18 15
A vulnerability has been found in D-Link DWR-M960 1
A vulnerability was found in D-Link DWR-M960 1
A vulnerability was determined in D-Link DWR-M960 1
A vulnerability was identified in D-Link DWR-M960 1
A security flaw has been discovered in D-Link DWR-M960 1
A weakness has been identified in Tenda A21 1
A vulnerability was identified in Tenda HG9 300001138
A security flaw has been discovered in Tenda HG9 300001138
A weakness has been identified in Tenda HG9 300001138
A security vulnerability has been detected in Tenda HG9 300001138
A vulnerability was detected in Tenda HG9 300001138
A flaw has been found in Tenda HG9 300001138
A vulnerability has been found in Tenda FH451 up to 1
A vulnerability was detected in D-Link DWR-M960 1
A flaw has been found in D-Link DWR-M960 1
A vulnerability has been found in D-Link DWR-M960 1
A vulnerability was found in D-Link DWR-M960 1
A vulnerability was determined in D-Link DWR-M960 1
A security vulnerability has been detected in D-Link DWR-M960 1
A vulnerability was detected in D-Link DWR-M960 1
A flaw has been found in D-Link DWR-M960 1
A vulnerability has been found in D-Link DWR-M960 1
A vulnerability was found in D-Link DWR-M960 1
An unauthenticated SQL injection vulnerability in microASP Portal+ CMS allows remote attackers to execute arbitrary SQL queries via the explode_tree parameter.
A high-severity vulnerability has been identified in the UTT HiPER 810G networking device, which could lead to unauthorized access or device compromise.
A vulnerability was found in UTT HiPER 810G up to 1
Web Wiz Forums 12
A DLL Hijacking vulnerability in eAI Technologies ERP allows authenticated local attackers to execute arbitrary code by placing a malicious DLL in the application directory.
The OpenClaw personal AI assistant contains a vulnerability that could allow for unauthorized access to personal data or the execution of unintended commands.
CollabPlatform is a full-stack, real-time doc collaboration platform
A vulnerability was determined in Zaher1307 tiny_web_server up to 8d77b1044a0ca3a5297d8726ac8aa2cf944d481b
A weakness has been identified in UTT HiPER 810G up to 1
A vulnerability has been found in UTT HiPER 810G up to 1