CVE-2012-1854
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's vulnerability landscape centers on Digiwin EasyFlow .NET and industrial control systems, with two CVSS 9.8 flaws in Digiwin products and a critical issue affecting SD-330AC and AMC Manager devices. The brief includes 3 critical vulnerabilities (down 57% from 7) and 22 high-priority CVEs (down 52% from 46), reflecting a quieter disclosure cycle. Key critical entries include CVE-2026-5963 and CVE-2026-5964 affecting Digiwin EasyFlow .NET, alongside CVE-2026-32956 impacting SD-330AC and AMC Manager processing. Business application platforms and industrial control systems dominate today's attack surface, with 9 CVEs showing confirmed active exploitation across Microsoft, Adobe, and Apache products. No patches are currently available for the disclosed critical vulnerabilities, warranting defensive monitoring and compensating controls until fixes are released.
Immediate action: Prioritize asset inventory and network isolation for Digiwin EasyFlow .NET deployments and SD-330AC/AMC Manager industrial devices pending vendor patches. Organizations running Microsoft Exchange, SharePoint, Windows, Adobe Acrobat, or Apache ActiveMQ should verify current patch levels given confirmed exploitation of the 9 KEV entries. No patches are available for today's critical CVEs, so apply network segmentation and enhanced monitoring until fixes are published.
Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Link Following Vulnerability - Active in CISA KEV catalog.
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Out-of-Bounds Read Vulnerability - Active in CISA KEV catalog.
Adobe Acrobat Use-After-Free Vulnerability - Active in CISA KEV catalog.
Adobe Acrobat Reader is vulnerable to prototype pollution, which can result in arbitrary code execution when a victim opens a malicious file.
Microsoft Office Remote Code Execution - Active in CISA KEV catalog.
Microsoft SharePoint Server Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Apache ActiveMQ Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.
Digiwin EasyFlow .NET contains a SQL injection vulnerability allowing unauthenticated remote attackers to manipulate database contents.
silex technology SD-330AC and AMC Manager contain a heap-based buffer overflow vulnerability, potentially allowing arbitrary code execution.
A vulnerability was determined in kodcloud KodExplorer up to 4
A vulnerability was identified in kodcloud KodExplorer up to 4
A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4
A security vulnerability exists in H3C Magic B0 routers up to version 100R002.
A security vulnerability exists in H3C Magic B1 routers up to version 100R004.
A security vulnerability exists in H3C Magic B1 routers up to version 100R004.
SD-330AC and AMC Manager provided by silex technology, Inc
TeamT5 ThreatSonar Anti-Ransomware contains an arbitrary file deletion vulnerability.
Initialization of a resource with an insecure default vulnerability exists in SD-330AC and AMC Manager provided by silex technology, Inc
A flaw has been found in dameng100 muucmf 1
A vulnerability exists in osuuu LightPicture up to version 1.
A vulnerability exists in liangliangyy DjangoBlog up to version 2.
A security vulnerability exists in liangliangyy DjangoBlog up to version 2.
A security flaw has been identified in TransformerOptimus SuperAGI that may impact system integrity.
A vulnerability has been identified in the brikcss merge utility that could potentially lead to security regressions.
A security flaw has been discovered in langflow-ai langflow that may expose the system to unauthorized operations.
A vulnerability has been determined in modelscope agentscope that could potentially impact system security.
A vulnerability has been identified in modelscope agentscope that could lead to potential security compromises.
A security flaw has been discovered in modelscope agentscope up to 1
A weakness has been identified in modelscope agentscope up to 1
A weakness has been identified in TransformerOptimus SuperAGI up to 0