Critical vulnerabilities, curated daily for security professionals
đ¯ SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
1 CISA KEV vulnerabilities with federal compliance deadlines
Enhanced AI analysis and EPSS scoring for accurate threat prioritization
đĄ Tip: Swipe CVE cards left to â star, right to â remove
Section Navigation
â ī¸
CISA Known Exploited Vulnerabilities
â ī¸ CISA KEVURGENT
CVE-2025-6543
9.5đ
CitrixNetscaler Adc
â° Federal Deadline:July 21, 2025(1 days remaining)
Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
đ¨
Critical Vulnerabilities
CVE-2025-20337
10đ
CiscoIdentity Services Engine
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root.
CVSS Base10
â
CRSSelect profile
CVE-2025-8901
9.8đ
The_bearsBears Backup Plugin
WordPress Bears Backup plugin is vulnerable to remote code execution in all versions up to 2.0.0 due to improper input validation in the backup restore functionality.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-7883
9.8đ
EluktronicsControl Center
A critical command injection vulnerability in Eluktronics Control Center allows authenticated attackers to execute arbitrary commands with elevated privileges.
CVSS Base9.8
â
CRSSelect profile
CVE-2025-9012
9.3đ
CmsjunkieWp Business Directory
SQL injection vulnerability in CMSJunkie WP-BusinessDirectory plugin allows blind SQL injection attacks through search parameters.