CVE-2025-43300
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 10 critical vulnerabilities and 32 high-priority updates requiring immediate attention.
Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Git Link Following Vulnerability - Active in CISA KEV catalog.
Citrix Session Recording Improper Privilege Management Vulnerability - Active in CISA KEV catalog.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX Authentication Bypass Vulnerability - Active in CISA KEV catalog.
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
Meta Platforms WhatsApp Incorrect Authorization Vulnerability - Active in CISA KEV catalog.
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability - Active in CISA KEV catalog.
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability - Active in CISA KEV catalog.
Android Runtime Use-After-Free Vulnerability - Active in CISA KEV catalog.
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. On systems that do not have hypervisor-protected code integrity (HVCI) enabled, entries...
The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'doccure_temp_upload_to_media' function in all versions up to, and including, 1.4.8. ...
The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.4.8. This is due to the plugin providing user-controlled access to objects, letting ...
rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.
WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIME types for Excel files at e...
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.
codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync command directly concatenates the user-controlled directoryPath parameter without s...
The Volkov Labs Business Links panel for Grafana provides an interface to navigate using external links, internal dashboards, time pickers, and dropdown menus. Prior to version 2.4.0, a malicious acto...
The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'doccure_temp_file_uploader' function in all versions up to, and including, 1
The Ditty WordPress plugin before 3
WeiPHP v5
A flaw has been found in PHPGurukul Small CRM 4
A low-privileged remote attacker could gain unauthorized access to critical resources, such as firmware and certificates, due to improper permission handling during the runtime of services (e
An authenticated, low-privileged attacker can obtain credentials stored on the charge controller including the manufacturer password
A vulnerability ( CVE-2025-21176 https://www
An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1
An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40
A vulnerability ( CVE-2024-38229 https://www
A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify App 1
A vulnerability (CVE-2025-21172) exists in msdia140
JSON::XS before version 4
JSON::SIMD before version 1
Assertion failure in function ngap_build_downlink_nas_transport in file src/amf/ngap-build
Due to an unsecure default configuration HTTP is used instead of HTTPS for the web interface
A flaw has been found in itsourcecode Online Discussion Forum 1
A weakness has been identified in SourceCodester Online Polling System 1
A security vulnerability has been detected in SourceCodester Online Polling System 1
A vulnerability was detected in SourceCodester Online Polling System 1
A vulnerability has been found in SourceCodester Online Polling System 1
A flaw has been found in Jinher OA up to 1
A vulnerability has been found in Jinher OA up to 1
A vulnerability was found in Jinher OA up to 1
FoxCMS v1
A vulnerability was detected in SourceCodester Simple Forum Discussion System 1
A security flaw has been discovered in code-projects Online Event Judging System 1
A weakness has been identified in code-projects Online Event Judging System 1
A security vulnerability has been detected in code-projects Online Event Judging System 1
A vulnerability was found in Campcodes Online Loan Management System 1
A vulnerability was determined in Campcodes Online Loan Management System 1
A security flaw has been discovered in itsourcecode Student Information Management System 1