CVE-2025-62593
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
Critical vulnerabilities, curated daily for security professionals
A large batch of IBM AIX and PowerVM VIOS vulnerabilities dominates yesterday's disclosures, joined by high-severity issues in Google Chrome, VMware Cloud Foundation, and SPIP. The day brought 26 critical CVEs (down 13% from 30) and 56 high-priority CVEs (down 8% from 61), for 82 total. Notable entries include CVE-2026-18835 (CVSS 9.9) in IBM AIX and PowerVM VIOS, CVE-2026-17924 (CVSS 9.6) in Google Chrome, and CVE-2026-77647 (CVSS 9.8) in SPIP. Remote code execution and privilege escalation against enterprise Unix, virtualization, and collaboration platforms are the recurring patterns, with 8 CVEs carrying confirmed active exploitation including Microsoft SharePoint, VMware vCenter, and Apple macOS. Patch availability is reported at 0% in this data set, so teams should track vendor advisories directly and apply mitigations or access restrictions while fixes are confirmed.
Immediate action: Prioritize IBM AIX and PowerVM VIOS estates given the volume of CVSS 9.8+ entries, then Google Chrome, VMware Cloud Foundation and vCenter, and Microsoft SharePoint where exploitation is already confirmed. Patch data shows 0% availability for these critical issues, so check vendor advisories for interim fixes and apply network restrictions, credential rotation, or exposure reduction on internet-facing instances until updates land.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Ray-Project Ray is affected by a code injection and CSRF vulnerability, allowing unauthenticated attackers to execute arbitrary code.
A double-free vulnerability in the Windows IKE Extension allows unauthenticated attackers to execute arbitrary code over a network.
VMware vCenter contains a directory traversal vulnerability in the Syslog server, which may allow an unauthenticated attacker with network access to execute arbitrary code on the system.
A weak authentication vulnerability in Microsoft SharePoint allows unauthenticated remote attackers to bypass security controls and access sensitive information.
An improper authentication flaw in Apple macOS Screen Sharing allows unauthenticated network attackers to bypass credentials and gain remote access.
TrueConf Server contains a vulnerability involving missing authentication for critical functions, which allows unauthorized remote attackers to perform sensitive actions.
MLflow contains a Server-Side Request Forgery (SSRF) vulnerability that allows unauthenticated attackers to reach internal services due to improper validation of redirected URLs.
TrueConf Server is affected by a code injection vulnerability that allows attackers to execute arbitrary code and escape isolated environments.
The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through another installed Remote A
Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
A stack-based buffer overflow in IBM AIX and PowerVM VIOS allows remote unauthenticated attackers to execute arbitrary code.
A buffer overflow vulnerability in IBM AIX and PowerVM VIOS permits remote unauthenticated attackers to execute arbitrary code.
A buffer overflow in IBM AIX and PowerVM VIOS allows remote unauthenticated attackers to execute arbitrary code.
A stack buffer overflow in IBM AIX and PowerVM VIOS allows remote, unauthenticated attackers to execute arbitrary code.
An OS command injection vulnerability in IBM AIX and PowerVM VIOS allows authenticated remote attackers to execute arbitrary commands.
SPIP versions prior to 4.4.20 are susceptible to unauthenticated remote code execution due to improper handling of PHP code blocks during processing.
A format string vulnerability in IBM AIX and PowerVM VIOS allows remote, unauthenticated attackers to execute arbitrary code.
IBM AIX and PowerVM VIOS contain an improper authentication vulnerability that allows remote, unauthenticated attackers to execute arbitrary commands on the system.
IBM AIX and PowerVM VIOS contain an improper privilege management vulnerability that enables remote, unauthenticated attackers to execute arbitrary code.
IBM AIX and PowerVM VIOS are affected by an integer overflow vulnerability during size computation, which allows remote, unauthenticated attackers to execute arbitrary code.
A deserialization vulnerability in Microsoft Entra ID allows unauthorized remote code execution and has been actively exploited in the wild.
The Automation Web Platform plugin for WordPress is vulnerable to an authentication bypass, allowing unauthenticated attackers to log in as any user, including administrators.
Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
The Wallet for WooCommerce plugin fails to verify payment completion before crediting user wallets, allowing attackers to inflate balances without providing valid payment.
The Comfast CF-N1-S Web Management interface contains a stack-based buffer overflow vulnerability in the ptest_channel configuration method, which can be triggered by authenticated remote attackers.
The Comfast CF-N1-S SSID configuration interface is vulnerable to a stack-based buffer overflow, allowing authenticated remote attackers to corrupt memory via the ssid parameter.
A remote code execution vulnerability exists in the Query Wrangler WordPress plugin, allowing authenticated subscribers to execute arbitrary code.
The IT Residence WordPress theme contains an arbitrary file upload vulnerability that allows authenticated subscribers to upload malicious files to the server.
The Smart Cleaning WordPress theme is vulnerable to an arbitrary file upload flaw, enabling authenticated subscribers to upload malicious content to the server.
Warehouse Cargo versions 2.6.9 and earlier allow authenticated subscribers to perform arbitrary file uploads, potentially leading to remote code execution.
The internment crate version 0.8.7 for Rust contains embedded malicious code that triggers arbitrary code execution during the project compilation process.
The append-only-vec crate version 0.1.9 for Rust contains embedded malicious code that executes during the compilation of any project that utilizes the crate.
The arrayref crate 0.3.10 for Rust contains malicious code that executes during project compilation by communicating with a command and control server to facilitate arbitrary code execution.
In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR chunk with a STALE_COOKIE cause is received in the COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure of Staleness that follows th
Use after free in Media in Google Chrome on Windows prior to 151.
LiquidJS is vulnerable to an infinite loop via a template processing flaw, which can lead to a denial of service.
The SimpleSAMLphp SAML2 library is susceptible to improper certificate validation, potentially allowing attackers to bypass authentication or integrity checks.
Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.
A Server-side request forgery (SSRF) vulnerability in Microsoft Azure Virtual Machines allows an authenticated attacker to perform unauthorized actions and escalate privileges over a network.
The Form Maker by 10Web plugin is susceptible to second-order SQL injection, allowing authenticated users to execute unauthorized database queries.
The Events Manager WordPress plugin contains a SQL injection vulnerability allowing authenticated users with subscriber-level privileges to modify booking consent records.
The Sony XAV-9500ES is vulnerable to a buffer overflow in its RTSP implementation, which could allow remote code execution.
NoMachine contains a command injection vulnerability in the getstat function, allowing an authenticated attacker to execute arbitrary system commands.
ZenHive mpp is vulnerable to an authentication bypass via a capture-replay attack, allowing unauthenticated attackers to obtain paid resources by resubmitting on-chain transfers.
The WP Photo Album Plus plugin contains a path traversal vulnerability that permits unauthenticated attackers to delete arbitrary ZIP files on the server.
Datiphy Data Management Center contains a missing authentication vulnerability in its upload API, allowing unauthenticated attackers to perform unauthorized file operations.
A prototype pollution vulnerability in the Time Series Visual Builder plugin for OpenSearch Dashboards allows authenticated remote code execution via crafted JSON payloads.
A resource exhaustion vulnerability in the mtrudel bandit library allows unauthenticated remote attackers to cause a denial-of-service via unbounded HTTP/2 stream process pinning.
A heap-based buffer overflow vulnerability in FreeRDP allows remote, unauthenticated attackers to potentially cause a crash or execute arbitrary code.
FreeRDP contains heap-based buffer overflow and integer overflow vulnerabilities that could allow an attacker to execute arbitrary code.
A heap-based buffer overflow vulnerability in FreeRDP may allow a remote attacker to execute arbitrary code.
The Grav API Plugin contains a missing authorization vulnerability that allows authenticated users to access sensitive content.
Talebook (MyBooks) is susceptible to a missing authorization vulnerability that allows authenticated users to perform unauthorized actions.
The Algernon web server is vulnerable to improper handling of Windows Alternate Data Streams, which can lead to unauthorized information disclosure.
A race condition in the Tor networking software allows for potential security bypasses due to improper synchronization of shared resources.
A security vulnerability in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allows a local authenticated attacker to achieve full system compromise.
An out-of-bounds write vulnerability in IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 allows an adjacent attacker to potentially execute arbitrary code or crash the system.
IBM AIX and PowerVM VIOS are susceptible to an out-of-bounds write vulnerability, which may allow an adjacent attacker to compromise system integrity and availability.
An out-of-bounds write vulnerability exists in IBM AIX and PowerVM VIOS, potentially allowing a local, authenticated attacker to gain escalated privileges or compromise the system.
IBM AIX and PowerVM VIOS are vulnerable to an out-of-bounds write, which may enable a local, authenticated attacker to achieve unauthorized control over the affected system.
IBM AIX and PowerVM VIOS are susceptible to an out-of-bounds write vulnerability, potentially allowing local attackers to execute arbitrary code with elevated privileges.
Dockge contains a path traversal vulnerability due to improper validation of stack names, which allows authenticated attackers to disclose arbitrary files and delete directories.
LangBot is affected by a command injection vulnerability that allows authenticated attackers to execute arbitrary system commands on the hosting platform.
IBM AIX and PowerVM VIOS are vulnerable to OS command injection, which can be triggered by a local authenticated attacker to execute arbitrary commands on the underlying operating system.
Genian NAC contains vulnerabilities involving improper input validation and exposure of sensitive information through data queries, allowing unauthorized access to internal data.
A vulnerability in libevent allows for an out-of-bounds read, potentially leading to application crashes or denial of service conditions.
An integer overflow vulnerability in libevent could allow remote, unauthenticated attackers to trigger a denial of service condition.
The Gameme module in ATutor 2.2.4 contains an unrestricted file upload vulnerability, allowing authenticated users to upload dangerous file types.
ATutor is vulnerable to a path traversal flaw in its ZIP extraction functionality, allowing authenticated users to manipulate file paths.
A path traversal vulnerability in n8n allows authenticated users to access or modify files outside of intended directories.
n8n is vulnerable to OS command injection, allowing authenticated users to execute arbitrary commands on the underlying system.
Netty is susceptible to an inefficient algorithmic complexity vulnerability that may allow for denial of service.
Logto is vulnerable to a path traversal attack that may allow unauthenticated attackers to access sensitive files.
Wekan is vulnerable to unrestricted file uploads, which could allow authenticated users to execute malicious code.
Akaunting 3.1.21 contains an incorrect authorization vulnerability that allows authenticated users to perform unauthorized actions.
Grav versions prior to 2.0.7 are susceptible to a code injection vulnerability that allows authenticated users to execute arbitrary code.
The J-BusinessDirectory extension for Joomla is vulnerable to resource exhaustion through improper limits on resource allocation, which can lead to denial of service conditions.
The SitemapLoader component in langchain-community versions up to 0.4.2 is vulnerable to Server-Side Request Forgery (SSRF) due to missing domain restrictions on nested sitemap entries.
Shaarli is vulnerable to a stored cross-site scripting (XSS) vulnerability, allowing an unauthenticated attacker to execute arbitrary scripts in the context of a user session.
The iCagenda extension for Joomla contains a cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into web pages.
The Phoca Cart extension for Joomla is susceptible to a cross-site scripting vulnerability that enables unauthenticated attackers to execute malicious scripts via user interaction.
An OS command injection vulnerability in vsDesk allows an authenticated administrator to execute arbitrary operating system commands via insufficient input filtering.
SiYuan note-taking software is vulnerable to cross-site scripting (XSS) that can be escalated to remote code execution (RCE) via unescaped block metadata in hint popups.
SiYuan is susceptible to a Cross-site Scripting vulnerability that can lead to remote code execution.
Stigmem contains an authorization bypass vulnerability allowing authenticated users to access data across tenant boundaries.
IBM AIX 7 and PowerVM VIOS 4.1 are affected by an out-of-bounds write vulnerability that could lead to unauthorized system access or service disruption.
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() br_ip6_fragment() gets prevhdr, a pointer into the skb head, from ip6_find_1stfragopt(), then calls skb_checksum_help().
In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() kvm_hyp_handle_mops() resets the single-step state machine as part of rewinding state for a MOPS exception by modifying vcpu_cpsr() and writing the result directly into.
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE.
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.