CVE-2025-47813
Wing FTP Server Information Disclosure Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Friday's vulnerability disclosures include a maximum-severity flaw in ORY Oathkeeper (CVE-2026-33494, CVSS 10.0) alongside critical issues in Incus (CVE-2026-33945, CVE-2026-33897, both CVSS 9.9) and OneUptime (CVE-2026-33396, CVSS 9.9). The day saw 11 critical CVEs, down 8% from Thursday, while 100 high-priority vulnerabilities held steady. HP products account for multiple critical entries (CVE-2026-33942, CVE-2026-4809), and WordPress (CVE-2026-4484) and SiYuan (CVE-2026-33669, CVE-2026-33670) each carry CVSS 9.8 scores. Nine vulnerabilities have confirmed active exploitation, notably affecting Apple products, Zimbra Collaboration Suite, Craft CMS, and Laravel Livewire. No patches are currently available for disclosed vulnerabilities, requiring organizations to prioritize compensating controls and monitoring.
Immediate action: Prioritize reviewing exposure to ORY Oathkeeper, Incus, OneUptime, and SiYuan deployments, and apply network-level restrictions where patches are unavailable. For the nine actively exploited vulnerabilities, verify compensating controls are in place for Apple products, Zimbra, Craft CMS, Laravel Livewire, Langflow, and Trivy, and monitor vendor channels for incoming patches.
Wing FTP Server Information Disclosure Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability - Active in CISA KEV catalog.
Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.
Laravel Livewire Code Injection Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Improper Locking Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Classic Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Aquasecurity Trivy Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
Saloon versions prior to 4.0.0 are vulnerable to PHP Object Injection via insecure use of unserialize() in the AccessTokenAuthenticator class, potentially leading to remote code execution.
Plank laravel-mediable through version 6.4.0 allows for arbitrary file upload and remote code execution by trusting client-supplied MIME types during the upload process.
The Masteriyo LMS plugin for WordPress allows authenticated Student-level users to escalate their privileges to Administrator via the InstructorsController.
Plack::Middleware::Session::Cookie through version 0.21 for Perl is vulnerable to remote code execution during cookie deserialization when no secret key is configured to sign session data.
ORY Oathkeeper versions prior to 26.2.0 are vulnerable to an authorization bypass via HTTP path traversal where raw paths are matched against permissive rules before normalization.
OneUptime versions prior to 10.0.35 allow low-privileged users to achieve remote code execution on the Probe container by escaping the Playwright sandbox via unblocked internal properties.
SiYuan versions prior to 3.6.2 are vulnerable to unauthorized data access where document IDs and content can be retrieved through the /api/file/readDir and /api/block/getChildBlocks interfaces.
SiYuan versions prior to 3.6.2 allow unauthenticated directory traversal and filename retrieval via the /api/file/readDir interface, exposing the structure of user notebooks.
Incus versions prior to 6.23.0 are vulnerable to an arbitrary file write flaw where path traversal in systemd credential keys allows root-level writes to the host filesystem.
Incus versions prior to 6.23.0 contain a critical sandbox escape in the pongo2 template implementation that allows arbitrary file reads and writes as root on the host server.
Spring AI versions prior to 1.0.5 and 1.1.4 are vulnerable to SpEL injection in SimpleVectorStore when user-supplied input is used as a filter expression key, leading to remote code execution.
A vulnerability in Cisco's IKEv2 implementation allows unauthenticated remote attackers to cause a memory leak. This leak eventually leads to a Denial of Service (DoS) condition on the affected network device.
A flaw in the DHCP snooping feature of Cisco IOS XE allows unauthenticated attackers to cause BOOTP packets to be forwarded between VLANs. This leads to a Denial of Service (DoS) condition.
A vulnerability in CAPWAP packet processing in Cisco IOS XE Wireless Controller Software allows unauthenticated remote attackers to cause a Denial of Service.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gaspard gaspard allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Good Homes good-homes allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Greenville greenville allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Hypnotherapy hypnotherapy allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Lella lella allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Mr
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Nelson nelson allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Amoli amoli allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Dentalux dentalux allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gioia gioia allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes NeoBeat neobeat allows PHP Local File Inclusion
OpenCart Core 4
Deserialization of Untrusted Data vulnerability in NooTheme Jobica Core jobica-core allows Object Injection
Deserialization of Untrusted Data vulnerability in NooTheme Visionary Core noo-visionary-core allows Object Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Miraculous Core Plugin miraculouscore allows Blind SQL Injection
HCL Aftermarket DPC is affected by SQL Injection which allows attacker to exploit this vulnerability to retrieve sensitive information from the database
The WP Job Portal plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'WPJOBPORTALcustomfields::removeFileCustom' function in all versions up to, and including, 2
The Amelia Booking plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 9
A security flaw has been discovered in Netcore Power 15AX up to 3
ClearanceKit for macOS contains a vulnerability in its file-system access event interception, potentially allowing bypass of per-process access policies.
etcd is a distributed key-value store for the data of a distributed system
Sharp is a content management framework built for Laravel as a package
Wecodex Hotel CMS 1
Online Store System CMS 1
OpenBiz Cubi Lite 3
A SQL Injection vulnerability has been found in Support Board v3
Sharp is a content management framework built for Laravel as a package
Pay is an open-source payment SDK extension package for various Chinese payment services
Docker BuildKit contains a vulnerability that could affect the efficiency and repeatability of build artifacts, potentially leading to unauthorized access or build-time exploits.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the Web management interface of certain ASUS router models
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products
Code injection vulnerability exists in BUFFALO Wi-Fi router products
Deserialization of Untrusted Data vulnerability in sbthemes WooCommerce Infinite Scroll sb-woocommerce-infinite-scroll allows Object Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Element Invader ElementInvader Addons for Elementor elementinvader-addons-for-elementor allows Blind SQL Injection
A stack-based buffer overflow vulnerability in the P2P API service in BS Producten Petcam with firmware 33
Deserialization of Untrusted Data vulnerability in thememount Apicona apicona allows Object Injection
A vulnerability was detected in Tenda AC5 15
A flaw has been found in Tenda AC5 15
A vulnerability has been found in Tenda AC5 15
A vulnerability was found in Tenda AC5 15
A vulnerability was determined in Tenda AC5 15
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal
Sonarr is a PVR for Usenet and BitTorrent users
Missing Authorization vulnerability in Devteam HaywoodTech Product Rearrange for WooCommerce products-rearrange-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels
ASP
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs
Improper Control of Generation of Code ('Code Injection') vulnerability in Saad Iqbal Post Snippets post-snippets allows Remote Code Inclusion
Authentication Bypass Using an Alternate Path or Channel vulnerability in Dokan, Inc
Deserialization of Untrusted Data vulnerability in NooTheme CitiLights noo-citilights allows Object Injection
Deserialization of Untrusted Data vulnerability in NooTheme Organici Library noo-organici-library allows Object Injection
Deserialization of Untrusted Data vulnerability in rascals Meloo meloo allows Object Injection
Deserialization of Untrusted Data vulnerability in rascals Pendulum pendulum allows Object Injection
Deserialization of Untrusted Data vulnerability in rascals Vex vex allows Object Injection
Authentication Bypass Using an Alternate Path or Channel vulnerability in Themeum Tutor LMS Pro tutor-pro allows Authentication Abuse
Incorrect Privilege Assignment vulnerability in iqonicdesign WPBookit Pro wpbookit-pro allows Privilege Escalation
Deserialization of Untrusted Data vulnerability in BoldGrid weForms weforms allows Object Injection
Deserialization of Untrusted Data vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows Object Injection
Incorrect Privilege Assignment vulnerability in WPFunnels Creator LMS creatorlms allows Privilege Escalation
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Organici Library noo-organici-library allows Blind SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team WZone woozone allows Blind SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection
Deserialization of Untrusted Data vulnerability in AncoraThemes Morning Records morning-records allows Object Injection
Deserialization of Untrusted Data vulnerability in AncoraThemes Melody melodyschool allows Object Injection
Kiteworks is a private data network (PDN)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AA-Team WZone woozone allows Path Traversal
OpenEMR is a free and open source electronic health records and medical practice management application
A vulnerability exists in the RPCSEC_GSS data packet validation routine where signature checks are improperly handled. This flaw could allow attackers to bypass security mechanisms.
A weakness has been identified in Wavlink WL-NU516U1 260227
A security vulnerability has been detected in UTT HiPER 1250GW up to 3
The VSL privileged helper does utilize NSXPC for IPC
EVerest is an EV charging software stack
Ory Polis, formerly known as BoxyHQ Jackson, bridges or proxies a SAML login flow to OAuth 2
vLLM is an inference and serving engine for large language models (LLMs)
Incus is a system container and virtual machine manager
OpenEMR is a free and open source electronic health records and medical practice management application
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Whitebox-Studio Scape scape allows Path Traversal
NATS-Server is a High-Performance server for NATS
Authorization Bypass Through User-Controlled Key vulnerability in Convers Lab WPSubscription subscription allows Exploiting Incorrectly Configured Access Control Security Levels
In TigerVNC before 1
Boxoft wav-wma Converter 1
Nsauditor 3
PDF Explorer 1
PassFab RAR Password Recovery 9
PassFab Excel Password Recovery 8
River Past CamDo 3 contains a high-severity vulnerability that could lead to unauthorized system access or execution. This late-disclosure entry requires immediate review for legacy systems.
EVerest is an EV charging software stack
EVerest is an EV charging software stack
Shipping System CMS 1
Wecodex Restaurant CMS 1
SAT CFDI 3
Library CMS 1
KomSeo Cart 1
qdPM 9
WebOfisi E-Ticaret 4
EVerest is an EV charging software stack