CVE-2025-57819
Sangoma FreePBX Authentication Bypass Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 8 critical vulnerabilities and 37 high-priority updates requiring immediate attention.
Sangoma FreePBX Authentication Bypass Vulnerability - Active in CISA KEV catalog.
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
Meta Platforms WhatsApp Incorrect Authorization Vulnerability - Active in CISA KEV catalog.
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability - Active in CISA KEV catalog.
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability - Active in CISA KEV catalog.
Android Runtime Use-After-Free Vulnerability - Active in CISA KEV catalog.
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Statistical Database System developed by Gotac has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents with high-level privi...
The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote code ex...
The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote cod...
The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59358, this allows unauthenticated in-cluster attackers to perform remote cod...
A vulnerability was detected in Mercury KM08-708H GiGA WiFi Wave2 1.1.14. This affects an unknown function of the component HTTP Header Handler. The manipulation of the argument Host results in stack-...
A vulnerability was found in Tenda AC1206 15.03.06.23. This vulnerability affects the function check_param_changed of the file /goform/AdvSetMacMtuWa of the component HTTP Request Handler. Performing ...
TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 function via the file_name parameter. This vulnerability allows unauthenticated attacke...
An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 w...
The MongoDB Windows installation MSI may leave ACLs unset on custom installation directories allowing a local attacker to introduce executable code to MongoDB's process via DLL hijacking
A flaw has been found in PHPGurukul Beauty Parlour Management System 1
A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1
A Cross-Site Request Forgery (CSRF) vulnerability was identified in the Profile Page of the PHPGurukul Student-Result-Management-System-Using-PHP-V2
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1
The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service
A vulnerability has been found in Mercury KM08-708H GiGA WiFi Wave2 1
A vulnerability was identified in Tenda AC9 and AC15 15
An issue was discovered in the method push
An issue was discovered in the method push
3DAlloy is a lightWeight 3D-viewer for MediaWiki
Relative path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution
In One Identity OneLogin before 2025
Mattermost versions 10
libexpat in Expat before 2
A vulnerability was determined in SourceCodester Pet Grooming Management Software 1
A vulnerability was found in itsourcecode Baptism Information Management System 1
A vulnerability was determined in itsourcecode Baptism Information Management System 1
A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1
A vulnerability was found in Campcodes Grocery Sales and Inventory System 1
A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1
A vulnerability was identified in Campcodes Grocery Sales and Inventory System 1
A security flaw has been discovered in Campcodes Grocery Sales and Inventory System 1
A vulnerability was determined in 1000projects Online Student Project Report Submission and Evaluation System 1
A vulnerability was identified in 1000projects Online Student Project Report Submission and Evaluation System 1
A security flaw has been discovered in itsourcecode Online Laundry Management System 1
A security flaw has been discovered in Campcodes Computer Sales and Inventory System 1
A weakness has been identified in Campcodes Computer Sales and Inventory System 1
A security flaw has been discovered in Campcodes Online Job Finder System 1
A weakness has been identified in Campcodes Computer Sales and Inventory System 1
A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1
Elevation of Privileges in the cleaning feature of Gen Digital CCleaner version 6
A vulnerability was detected in Campcodes Online Job Finder System 1
A flaw has been found in Campcodes Online Job Finder System 1
A null pointer dereference vulnerability was discovered in SumatraPDF 3
A security flaw has been discovered in SourceCodester Online Student File Management System 1
A vulnerability was detected in SourceCodester Online Student File Management System 1