CVE-2025-6554
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
Tuesday's Security Snapshot: High-Volume Alert Day
Immediate action: Immediate patching required for Google Chromium V8 KEV vulnerability expiring today
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Rails Ruby on Rails Path Traversal Vulnerability - Active in CISA KEV catalog.
PHPMailer Command Injection Vulnerability - Active in CISA KEV catalog.
Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability - Active in CISA KEV catalog.
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Fortinet FortiWeb SQL Injection Vulnerability - Active in CISA KEV catalog.
The SFT developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to pre-auth remote code execution, if a specific conf...
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. Th...
A reflected cross-site scripting (XSS) vulnerability was discovered in index.php on Luxcal 4.5.2 which allows an unauthenticated attacker to steal other users' data.
An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote code execution, if a quarantining policy is active for...
WinMatrix3 developed by Simopro Technology has an Insecure Deserialization vulnerability, allowing unauthenticated remote attackers to execute arbitrary code on the server by sending maliciously craft...
WinMatrix3 Web package developed by Simopro Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete databas...
Certain modem models developed by Askey has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and potentially execute arbit...
Manager-io/Manager is accounting software. A critical unauthenticated full read Server-Side Request Forgery (SSRF) vulnerability has been identified in the proxy handler component of both manager Desk...
Due to insufficient verification, an attacker could use a malicious client to bypass authentication checks and run RPC commands in a region. This has been addressed in MAAS and updated in the correspo...
Mbed TLS before 3
The EAI developed by Digiwin has a Privilege Escalation vulnerability, allowing remote attackers with regular privileges to elevate their privileges to administrator level via a specific API
Luxion KeyShot 3DM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21
A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21
CWE-434 Unrestricted Upload of File with Dangerous Type
A vulnerability was found in D-Link DI-8100 1
A vulnerability was found in D-Link DIR-513 1
A vulnerability classified as critical has been found in D-Link DIR-513 1
A vulnerability classified as critical was found in D-Link DI-8100 1
A vulnerability, which was classified as critical, has been found in TOTOLINK T6 4
A vulnerability, which was classified as critical, was found in TOTOLINK T6 4
A vulnerability has been found in Tenda AC6 15
File access paths in configuration files uploaded by users with administrator access are not validated
An issue was discovered in CommScope Ruckus Unleashed prior to 200
An issue was discovered in CommScope Ruckus Unleashed prior to 200
CWE-918 Server-Side Request Forgery (SSRF)
An issue was discovered in Eveo URVE Web Manager 27
An issue was discovered in Logpoint before 7
A vulnerability classified as critical has been found in Eluktronics Control Center 5
Insufficient protection against brute-force and runtime manipulation in the local authentication component in Two App Studio Journey 5
Multiple IrfanView CADImage Plugin vulnerabilities (139 CVEs)
Multiple INVT VT-Designer PM3 parsing vulnerabilities (9 CVEs)