CVE-2025-66376
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's vulnerability disclosures are dominated by critical flaws in MLflow and OpenClaw, with a perfect CVSS 10.0 remote code execution vulnerability in MLflow (CVE-2025-15379) and five additional critical OpenClaw vulnerabilities scoring 9.8-9.9. The day's 68 disclosed CVEs include 7 critical and 61 high-priority issues, with high-severity volume dropping 38% from the prior day while critical counts held steady. Eight vulnerabilities have confirmed active exploitation, targeting Apple products, Zimbra Collaboration Suite, Craft CMS, Laravel Livewire, Langflow, and Aquasecurity Trivy. Attack patterns center on remote code execution and authentication bypass across both ML/AI platforms and widely deployed enterprise software. No patches are currently available for any of the disclosed vulnerabilities, requiring defenders to rely on compensating controls and network-level mitigations.
Immediate action: Organizations running MLflow, OpenClaw, Apple products, Zimbra, Craft CMS, Laravel Livewire, Langflow, or Trivy should audit exposure immediately and apply network segmentation or access restrictions as interim mitigations. With zero patches currently available, prioritize monitoring for exploitation indicators and restrict public-facing access to affected services until vendor fixes are released.
Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability - Active in CISA KEV catalog.
Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.
Laravel Livewire Code Injection Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Improper Locking Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Classic Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Aquasecurity Trivy Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
A command injection vulnerability in MLflow's model serving container initialization allows attackers to execute arbitrary commands by supplying malicious model artifacts with unsanitized dependencies.
A privilege escalation vulnerability in OpenClaw's token rotation mechanism allows users with limited pairing scopes to mint high-privilege administrative tokens and achieve remote code execution.
A path traversal vulnerability in MLflow's archive extraction function allows attackers to overwrite arbitrary files and escape sandboxed directories via malicious tar archives.
OpenClaw's device pairing process is vulnerable to a replay attack where bootstrap setup codes can be reused to escalate pairing scopes to administrative levels.
An authorization bypass in OpenClaw's Feishu integration misclassifies group chat reaction events as private conversations, allowing attackers to circumvent group security protections.
An execution allowlist bypass in OpenClaw due to improper path normalization and glob matching allows attackers to execute unauthorized commands on the system.
A weak authorization vulnerability in OpenClaw's Zalouser allowlist mode allows attackers to bypass channel authorization by spoofing mutable group display names.
A critical vulnerability has been disclosed in the NRSS RSS Reader version 0.x. This flaw could lead to significant system compromise if exploited by a remote attacker.
The Download Monitor plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) flaw. This allows unauthorized access to restricted files in versions up to 5.x.
A security flaw has been discovered in code-projects Simple Food Order System 1
A weakness has been identified in code-projects Simple Food Order System 1
A security vulnerability has been detected in code-projects Simple Food Order System 1
A vulnerability was detected in code-projects Accounting System 1
A flaw has been found in code-projects Accounting System 1
A vulnerability has been found in code-projects Accounting System 1
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability
A flaw has been found in Tenda F453 1
A vulnerability was found in D-Link DIR-513 1
A vulnerability was detected in Tenda FH1201 1
A flaw has been found in Tenda FH1201 1
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14
Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability
OpenClaw before 2026
An unauthenticated remote attacker can exploit insufficient input validation to access backend components beyond their intended scope via path traversal, resulting in exposure of sensitive information
An integer overflow vulnerability in the HTTP chunked transfer encoding parser in tinyproxy up to and including version 1
A high-severity vulnerability has been identified in the Wavlink WL-WN579X3-C router, version 231124, which could allow for remote exploitation.
A vulnerability was found in Tenda 4G06 04
A security flaw has been discovered in the Belkin F9K1122 router, potentially allowing for unauthorized access or system interference.
A security weakness has been identified in the Belkin F9K1122 router that could be exploited to compromise the device's security posture.
OpenClaw before 2026
OpenClaw before 2026
OpenClaw before 2026
A security vulnerability has been detected in the Belkin F9K1122 router, potentially enabling attackers to gain unauthorized access or disrupt services.
A critical vulnerability exists in the Sofia component of Xiongmai DVR/NVR devices. This flaw allows attackers to potentially compromise the surveillance system's integrity and availability.
Ghidra versions prior to 12
OpenClaw before 2026
xwpe 1
yTree 1
Multi Emulator Super System 0
TiEmu 3
Yasr 0
TRN 3
PInfo 0
HNB Organizer 1
zFTP Client 20061220+dfsg3-4
EKG Gadu 1
iSelect 1
Mapscrn 2
Flat Assembler 1
A late-disclosure high-severity vulnerability affects SC v7, potentially leading to unauthorized system access or arbitrary code execution.
PMS 0
SIPP 3
OpenClaw before 2026
OpenClaw before 2026
A critical security vulnerability in parisneo/lollms versions up to 2
OpenClaw before 2026
OpenClaw before 2026
A vulnerability in parisneo/lollms, up to and including version 2
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2
Sinaptik AI PandasAI is vulnerable to a security flaw in versions up to 0.x. This vulnerability could allow for unauthorized data manipulation or information disclosure.
A security weakness has been identified in Sinaptik AI PandasAI versions up to 3.x. This flaw may allow attackers to compromise the security of the data analysis environment.
A vulnerability was detected in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054
A flaw has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054
A vulnerability has been found in PromtEngineer localGPT up to 4d41c7d1713b16b216d8e062e51a5dd88b20b054
A flaw has been found in elecV2 elecV2P up to 3
A vulnerability was identified in elecV2 elecV2P up to 3
OpenClaw before 2026
OpenClaw before 2026