CVE-2025-48384
Git Link Following Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
This curated brief highlights 1 critical vulnerabilities and 14 high-priority updates requiring immediate attention.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Git Link Following Vulnerability - Active in CISA KEV catalog.
Citrix Session Recording Improper Privilege Management Vulnerability - Active in CISA KEV catalog.
Citrix Session Recording Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Sangoma FreePBX Authentication Bypass Vulnerability - Active in CISA KEV catalog.
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
Meta Platforms WhatsApp Incorrect Authorization Vulnerability - Active in CISA KEV catalog.
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability - Active in CISA KEV catalog.
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability - Active in CISA KEV catalog.
Android Runtime Use-After-Free Vulnerability - Active in CISA KEV catalog.
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-...
A flaw has been found in PHPGurukul Beauty Parlour Management System 1
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1
A vulnerability has been found in Mercury KM08-708H GiGA WiFi Wave2 1
In One Identity OneLogin before 2025
A security vulnerability has been detected in Wavlink WL-WN578W2 221110
A vulnerability was detected in Wavlink WL-WN578W2 221110
A security flaw has been discovered in eCharge Hardy Barth Salia PLCC 2
A security flaw has been discovered in Shenzhen Sixun Business Management System 7/11
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1
A vulnerability was found in itsourcecode Baptism Information Management System 1
A vulnerability was determined in itsourcecode Baptism Information Management System 1
A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1
A vulnerability was found in Campcodes Grocery Sales and Inventory System 1
A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1