CVE-2025-25257
Fortinet FortiWeb SQL Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
Monday's weekend security briefing covers 8 actively exploited vulnerabilities with federal compliance deadlines, plus 27 newly disclosed high-priority vulnerabilities that require immediate patching.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Fortinet FortiWeb SQL Injection Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability - Active in CISA KEV catalog.
CrushFTP Unprotected Alternate Channel Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in versions 1
NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges
NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under normal use cases
NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted parameters
NVIDIA GPU Display Driver for Windows contains a vulnerability where an attacker with local unprivileged access that can win a race condition might be able to trigger a use-after-free error
NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stack buffer overflow
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause a stack buffer overflow
In iperf before 3
OpenNebula Community Edition (CE) before 7
Copyparty is a portable file server
A vulnerability was found in code-projects Online Farm System 1
A vulnerability was found in code-projects Wazifa System 1
A vulnerability was found in code-projects Wazifa System 1
A vulnerability classified as critical has been found in SourceCodester Online Hotel Reservation System 1
A vulnerability classified as critical was found in SourceCodester Online Hotel Reservation System 1
A vulnerability, which was classified as critical, has been found in projectworlds Online Admission System 1
A vulnerability classified as critical was found in code-projects Intern Membership Management System 1
A vulnerability, which was classified as critical, has been found in code-projects Intern Membership Management System 1
A vulnerability, which was classified as critical, was found in code-projects Intern Membership Management System 1
A vulnerability has been found in projectworlds Online Admission System 1
A vulnerability was found in code-projects Online Medicine Guide 1
A vulnerability was found in code-projects Online Medicine Guide 1
A vulnerability was found in code-projects Online Medicine Guide 1
A vulnerability classified as critical was found in code-projects Online Medicine Guide 1
A vulnerability, which was classified as critical, has been found in code-projects Online Medicine Guide 1
Cursor is a code editor built for programming with AI
NVIDIA