CVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's security brief highlights 6 actively exploited vulnerabilities and 29 high-priority updates demanding immediate attention across federal and enterprise environments.
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Fortinet FortiWeb SQL Injection Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability - Active in CISA KEV catalog.
CrushFTP Unprotected Alternate Channel Vulnerability - Active in CISA KEV catalog.
The GeoDirectory â WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to time-based SQL Injection via the dist parameter in all versions up to, and including, 2
HAX CMS allows you to manage your microsite universe with PHP or NodeJs backends
The Kallyas theme for WordPress is vulnerable to arbitrary folder deletion due to insufficient file path validation in the delete_font() function in all versions up to, and including, 4
The MinimogWP â The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3
The kallyas theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4
A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2
A vulnerability classified as critical has been found in Tenda AC10 16
A vulnerability, which was classified as critical, has been found in Tenda CH22 1
A vulnerability was found in D-Link DIR-513 up to 1
A vulnerability has been found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
A sandbox escape vulnerability was identified in huggingface/smolagents version 1
A vulnerability was found in 1000 Projects ABC Courier Management System 1
A vulnerability classified as critical has been found in Engeman Web up to 12
A vulnerability, which was classified as critical, was found in code-projects Online Ordering System 1
A vulnerability has been found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1
A vulnerability classified as critical was found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1
A vulnerability, which was classified as critical, was found in TOTOLINK N600R and X2000R 1
LinuxServer