CVE-2025-2775
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 3 critical vulnerabilities and 38 high-priority updates requiring immediate attention.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability - Active in CISA KEV catalog.
Google Chromium ANGLE and GPU Improper Input Validation Vulnerability - Active in CISA KEV catalog.
CrushFTP Unprotected Alternate Channel Vulnerability - Active in CISA KEV catalog.
PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
Cisco Identity Services Engine Injection Vulnerability - Active in CISA KEV catalog.
D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability - Active in CISA KEV catalog.
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability - Active in CISA KEV catalog.
D-Link DNR-322L Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
Official Document Management System developed by 2100 Technology has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to obtain any user's connection token and use it ...
ModelCache for LLM through v0.2.0 was discovered to contain an deserialization vulnerability via the component /manager/data_manager.py. This vulnerability allows attackers to execute arbitrary code v...
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.6, 7.3.13, and 7.2.8 contain a SQL injection vulnerability in the `processAsyncObject` meth...
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station
Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability
Mattermost Confluence Plugin version <1
Mattermost Confluence Plugin version <1
Mattermost Confluence Plugin version <1
Mattermost Confluence Plugin version <1
Server-Side Request Forgery (SSRF) in Omnissa Secure Email Gateway (SEG) in SEG prior to 2
Stirling-PDF is a locally hosted web application that performs various operations on PDF files
Stirling-PDF is a locally hosted web application that performs various operations on PDF files
Stirling-PDF is a locally hosted web application that performs various operations on PDF files
A vulnerability classified as critical was found in Tenda AC20 16
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability has been found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was found in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
A vulnerability was identified in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 up to 20250801
Catalyst::Authentication::Credential::HTTP versions 1
in OpenHarmony v5
in OpenHarmony v5
in OpenHarmony v5
in OpenHarmony v5
Cherry Studio is a desktop client that supports for multiple LLM providers
Missing Authentication for Critical Function vulnerability in ABB Aspect
Missing Authentication for Critical Function vulnerability in ABB Aspect
A vulnerability was found in oitcode samarium up to 0
A vulnerability classified as critical has been found in code-projects Online Medicine Guide 1
A vulnerability, which was classified as critical, has been found in code-projects Simple Art Gallery 1
A vulnerability was found in įĢåŽi Morning up to bc782730c74ff080494f145cc363a0b4f43f7d3e
A vulnerability has been found in WinterChenS my-site up to 1f7525f15934d9d6a278de967f6ec9f1757738d8
Improper Control of Generation of Code ('Code Injection') vulnerability in ABB ASPECT
Insufficiently Protected Credentials vulnerability in ABB Aspect
Authorization Bypass Through User-Controlled Key vulnerability in ABB Aspect
A vulnerability in ABB Aspect