CVE-2025-53770
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.
Critical vulnerabilities, curated daily for security professionals
This curated brief highlights 10 actively exploited vulnerabilities, 3 critical vulnerabilities, and 37 high-priority updates requiring immediate attention.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild.
TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability - Active in CISA KEV catalog.
TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability - Active in CISA KEV catalog.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Rails Ruby on Rails Path Traversal Vulnerability - Active in CISA KEV catalog.
PHPMailer Command Injection Vulnerability - Active in CISA KEV catalog.
Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Fortinet FortiWeb SQL Injection Vulnerability - Active in CISA KEV catalog.
WordPress Bears Backup plugin is vulnerable to remote code execution in all versions up to 2.0.0 due to improper input validation in the backup restore functionality.
SQL injection vulnerability in CMSJunkie WP-BusinessDirectory plugin allows blind SQL injection attacks through search parameters.
A critical command injection vulnerability in Eluktronics Control Center allows authenticated attackers to execute arbitrary commands with elevated privileges.
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1
The Simple Backup plugin for WordPress is vulnerable to Arbitrary File Download in versions up to, and including, 2
The GI-Media Library plugin for WordPress is vulnerable to Directory Traversal in versions before 3
The Subscribe to Comments for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2
Mbed TLS before 3
A vulnerability was found in TOTOLINK T6 4
A vulnerability was found in Tenda FH451 1
A vulnerability classified as critical has been found in Tenda FH451 1
A vulnerability classified as critical was found in Tenda FH451 1
CWE-434 Unrestricted Upload of File with Dangerous Type
A vulnerability was found in D-Link DI-8100 1
A vulnerability was found in D-Link DIR-513 1
A vulnerability classified as critical has been found in D-Link DIR-513 1
A vulnerability classified as critical was found in D-Link DI-8100 1
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4
A vulnerability has been found in Tenda AC6 15
CWE-918 Server-Side Request Forgery (SSRF)
An issue was discovered in Logpoint before 7
A vulnerability classified as critical has been found in Eluktronics Control Center 5
eslint-config-prettier 8
A vulnerability was found in Jinher OA 1
A vulnerability was found in Jinher OA 1
A vulnerability was found in code-projects Church Donation System 1
A vulnerability was found in code-projects Church Donation System 1
A vulnerability classified as critical has been found in code-projects Church Donation System 1
A vulnerability classified as critical was found in code-projects Church Donation System 1
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1
A vulnerability has been found in Campcodes Online Movie Theater Seat Reservation System 1
A vulnerability classified as critical was found in code-projects Church Donation System 1
A vulnerability, which was classified as critical, has been found in code-projects Church Donation System 1
A vulnerability, which was classified as critical, was found in code-projects Church Donation System 1
A vulnerability has been found in TOTOLINK T6 4
A vulnerability classified as critical has been found in Metasoft 美特软件 MetaCRM up to 6
A vulnerability, which was classified as critical, was found in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486
A vulnerability was found in harry0703 MoneyPrinterTurbo up to 1
A vulnerability was found in Chanjet CRM 1