CVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 6 critical vulnerabilities and 52 high-priority updates requiring immediate attention.
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Fortinet FortiWeb SQL Injection Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability - Active in CISA KEV catalog.
CrushFTP Unprotected Alternate Channel Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilities. An attacker can...
CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affects applications that use the ImageMagick handler for image processing (`imagick...
RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language. In versions below 1.0.1, a valid MongoDB Atlas URI with embedded use...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ncvav Virtual PBX Software allows SQL Injection.This issue affects Virtual PBX Software: before 09...
A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from the (unsigned) original response document. This is different than the parts that ...
An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application can decrypt credentia...
Incorrect Use of Privileged APIs vulnerability in Beamsec PhishPro allows Privilege Abuse
There is a defect in the CPython âtarfileâ module affecting the âTarFileâ extraction and entry enumeration APIs
An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1
A vulnerability has been found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
A vulnerability was found in TOTOLINK X15 1
Insufficient input validation within GitLab Language Server 7
Versions of the package ssrfcheck before 1
In JetBrains TeamCity before 2025
A sandbox escape vulnerability was identified in huggingface/smolagents version 1
IBM Informix Dynamic Server 12
Improper session invalidation in the component /elms/emp-changepassword
Improper session invalidation in the component /doctor/change-password
Improper session invalidation in the component /doctor/change-password
In JetBrains TeamCity before 2025
Improper session invalidation in the component /srms/change-password
Improper session invalidation in the component /edms/change-password
A vulnerability classified as critical has been found in Engeman Web up to 12
A vulnerability, which was classified as critical, was found in code-projects Online Ordering System 1
A vulnerability has been found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Online Ordering System 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1
A vulnerability classified as critical was found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1
A vulnerability classified as critical was found in code-projects Online Ordering System 1
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, was found in code-projects Exam Form Submission 1
A vulnerability has been found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, was found in Vaelsys 4
A vulnerability was found in Vaelsys 4
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1
LinuxServer
Improper session invalidation in the component /library/change-password
Improper session invalidation in the component /banker/change-password
Improper session invalidation in the component /crm/change-password
Improper session invalidation in the component /bbdms/change-password
Improper session invalidation in the component /crm/change-password
Improper session invalidation in the component /carrental/update-password