CVE-2025-2775
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
This curated brief highlights 2 critical vulnerabilities and 15 high-priority updates requiring immediate attention.
CVSS score (e.g. 9.1) โ severity from 0โ10. Red marks critical (9+), orange high (7โ8.9).
Exploitability โ how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale โ โNetwork ยท No privileges ยท No interactionโ is the worst case: hit from anywhere, no credentials, no victim action.
๐ด Actively exploited โ confirmed under attack in the wild (CISAโs Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS ยท Nth percentile โ FIRST.orgโs estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% โ a statistical signal itโs unusually likely to be targeted, separate from whether attacks are confirmed.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability - Active in CISA KEV catalog.
CrushFTP Unprotected Alternate Channel Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability - Active in CISA KEV catalog.
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability - Active in CISA KEV catalog.
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
The Assemblyline 4 Service Client interfaces with the API to fetch tasks and publish the result for a service in Assemblyline 4. In versions below 4.6.1.dev138, the Assemblyline 4 Service Client (task...
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intention...
The AuthKit library for React Router 7+ provides helpers for authentication and session management using WorkOS & AuthKit with React Router
A vulnerability classified as critical was found in Tenda AC20 16
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability classified as critical was found in CesiumLab Web up to 4
A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562
A vulnerability, which was classified as critical, was found in Dinstar Monitoring Platform ็่็ๅฑ้ฉๅๅบ็ๆงๅนณๅฐ 1
A vulnerability was found in oitcode samarium up to 0
A vulnerability classified as critical has been found in code-projects Online Medicine Guide 1
A vulnerability, which was classified as critical, has been found in code-projects Simple Art Gallery 1
A vulnerability was found in ็ซๅฎi Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys
The AuthKit library for Remix provides convenient helpers for authentication and session management using WorkOS & AuthKit with Remix
A vulnerability was found in TRENDnet TV-IP110WN 1
A vulnerability was found in TRENDnet TEW-822DRE FW103B02