CVE-2025-47812
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 34 critical vulnerabilities and 84 high-priority updates requiring immediate attention.
Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability - Active in CISA KEV catalog.
Fortinet FortiWeb SQL Injection Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability - Active in CISA KEV catalog.
CrushFTP Unprotected Alternate Channel Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
This issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app acting as a HTTPS proxy could get acce...
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, iPadOS 17.7.9, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to fingerprint t...
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in macOS Sonoma 14.7.7, macOS Ventura 13.7.7, macOS Sequoia 15.4. A shortcut may be able to bypass sensiti...
The issue was addressed with improved memory handling. This issue is fixed in watchOS 11.6, iOS 18.6 and iPadOS 18.6, tvOS 18.6, macOS Sequoia 15.6, macOS Sonoma 14.7.7, visionOS 2.6, macOS Ventura 13...
This issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to read kernel memory.
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. Account-driven User Enrollment may still be possible with Lockdown Mod...
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.6, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to cause a denial-of-service.
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to modify protected parts of the file system.
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. An app may be able to access protected user data.
A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. A malicious app may be able to gain root privil...
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6, iPadOS 17.7.9, iOS 18.6 and iPadOS 18.6, tvOS 18.6, macOS Sonoma 14.7.7, watchOS 1...
This issue was addressed with improved validation of symlinks. This issue is fixed in iPadOS 17.7.9, macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protect...
A use-after-free issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.6, iPadOS 17.7.9, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An attacker may be able to ca...
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to bypass certain Privacy prefe...
Multiple memory corruption issues were addressed with improved input validation. This issue is fixed in watchOS 11.6, iOS 18.6 and iPadOS 18.6, tvOS 18.6, macOS Sequoia 15.6, visionOS 2.6. Processing ...
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.6. An app may be able to cause unexpected system termination.
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Ventura 13.7.7, macOS Sonoma 14.7.7. An app may be able to modify protected parts of th...
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termina...
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to access protected ...
This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7. A malicious app may be able to launch arbitrary binaries on a trusted device.
A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.
A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to break out of its sandbox.
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.6 and iPadOS 18.6. Passcode may be read aloud by VoiceOver.
An input validation issue was addressed with improved memory handling. This issue is fixed in visionOS 2.6, tvOS 18.6, macOS Sequoia 15.6, iOS 18.6 and iPadOS 18.6. Processing a maliciously crafted fi...
A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6. A sandboxed process may be able to circumvent sandbox restrictions.
dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution quickly on structured data. Before commit 3f61e79, a critical severity vulnerabilit...
A Missing Authentication for Critical Function vulnerability in SUSE Manager allows anyone with access to the websocket at /rhn/websocket/minion/remote-commands to execute arbitrary commands as root. ...
LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipul...
An access control issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to access the router's settings file and obtain potentially sensitive information from the curren...
Marvell QConvergeConsole compressConfigFiles Directory Traversal Information Disclosure and Denial-of-Service Vulnerability. This vulnerability allows remote attackers to disclose sensitive informatio...
OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrated into existing reverse proxy or load balancer setups. In versions 7.10.0 and b...
An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated attackers to execute arbitrary commands as root via crafted input to the hostname...
An issue in Intelbras RX1500 v2.2.9 and RX3000 v1.0.11 allows unauthenticated attackers to execute arbitrary code via injecting a crafted payload into the ESSID name when creating a network.
GÃŧralp FMUS series seismic monitoring devices expose an unauthenticated Telnet-based command line interface that could allow an attacker to modify hardware configurations, manipulate data, or factor...
Use after free in Media Stream in Google Chrome prior to 138
The AI Engine plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_simpleFileUpload() function in versions 2
A stored cross-site scripting (XSS) vulnerability exists in DevaslanPHP project-management v1
A carefully crafted request when creating a header link using the wiki markup syntax, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim
php-jwt v6
The NinjaScanner â Virus & Malware scan plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'nscan_ajax_quarantine' and 'nscan_quarantine_select' functions in all versions up to, and including, 3
Dell XtremIO, version(s) 6
Dell Encryption and Dell Security Management Server, versions prior to 11
Tesla Wall Connector Content-Length Header Improper Input Validation Remote Code Execution Vulnerability
The e-School from Ventem has a Missing Authorization vulnerability, allowing remote attackers with regular privilege to access administrator functions, including creating, modifying, and deleting accounts
The e-School from Ventem has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server
vproxy is an HTTP/HTTPS/SOCKS5 proxy server
An unauthenticated remote attacker can cause a Denial of Service by sending a large number of requests to the http service on port 80
A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox
GitProxy is an application that stands between developers and a Git remote endpoint
The issue was addressed with improved memory handling
The issue was addressed with improved memory handling
The issue was addressed with improved memory handling
An access issue was addressed with additional sandbox restrictions
TechAdvisor versions 2
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K
An issue was discovered in Archer Technology RSA Archer 6
TrustedFirmware-M (aka Trusted Firmware for M profile Arm CPUs) before 2
An issue was discovered in CS Cart 4
An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions
An uncontrolled search path element vulnerability can lead to local privilege Escalation (LPE) via Insecure Directory Permissions
The vulnerability was identified in the code developed specifically for Lenovo
The vulnerability was identified in the code developed specifically for Lenovo
The vulnerability was identified in the code developed specifically for Lenovo
The vulnerability was identified in the code developed specifically for Lenovo
GetProjectsIdea Create School Management System 1
An issue in Aver PTC310UV2 v
Ceph is a distributed object, block, and file storage platform
CS Cart 4
A Broken Access Control vulnerability in MagnusBilling v7
This issue was addressed through improved state management
A permissions issue was addressed with additional restrictions
A memory corruption issue was addressed with improved validation
A permissions issue was addressed with additional restrictions
A path handling issue was addressed with improved validation
A logic issue was addressed with improved restrictions
A logic issue was addressed with improved checks
This issue was addressed through improved state management
The issue was addressed with improved memory handling
The firmware of the AZIOT 2MP Full HD Smart Wi-Fi CCTV Home Security Camera (version V1
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents
A Stored Cross-Site Scripting (XSS) vulnerability in Microweber CMS 2
The issue was addressed with improved checks
A denial-of-service issue was addressed with improved input validation
This issue was addressed through improved state management
A vulnerability classified as critical has been found in code-projects Exam Form Submission 1
Rocket Software Rocket Zena 4
A vulnerability classified as critical was found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, has been found in code-projects Exam Form Submission 1
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1
A vulnerability has been found in code-projects Vehicle Management 1
A vulnerability was found in code-projects Online Farm System 1
A vulnerability was found in code-projects Online Farm System 1
A vulnerability was found in code-projects Online Farm System 1
A vulnerability was found in Campcodes Online Recruitment Management System 1
A vulnerability classified as critical was found in Campcodes Online Recruitment Management System 1
A vulnerability was found in projectworlds Online Admission System 1
A vulnerability was found in code-projects Intern Membership Management System 1
A vulnerability has been found in Kehua Charging Pile Cloud Platform 1
A vulnerability has been found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Exam Form Submission 1
A vulnerability was found in code-projects Vehicle Management 1
A vulnerability was found in code-projects Vehicle Management 1
A vulnerability was found in code-projects Vehicle Management 1
A vulnerability classified as critical has been found in code-projects Vehicle Management 1
A vulnerability was found in Campcodes Online Hotel Reservation System 1
A vulnerability, which was classified as critical, has been found in code-projects Vehicle Management 1
A vulnerability, which was classified as critical, was found in code-projects Vehicle Management 1
ExaGrid EX10 6
A vulnerability has been found in code-projects Vehicle Management 1
A cross-site scripting (XSS) vulnerability in Intelbras RX1500 v2
A path traversal issue exists in backup and restore feature of multiple versions of PowerCMS
An out-of-bounds access issue was addressed with improved bounds checking
An out-of-bounds access issue was addressed with improved bounds checking
An out-of-bounds access issue was addressed with improved bounds checking
An out-of-bounds read was addressed with improved input validation
Deadlock in PAM automatic check-in feature in Devolutions Server allows a password to remain valid beyond the end of its intended check-out period due to a deadlock occurring in the scheduling service
jwt v5
pyjwt v2