CVE-2020-24363
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Tuesday's threat landscape demands urgent action with federal KEV deadlines expiring TODAY for TP-Link TL-WR841N router (CVE-2023-50224) and multiple TP-Link routers (CVE-2025-9377). Additionally, a CVSS 10.0 maximum-severity flaw in Flowise (CVE-2025-59528) enables remote code execution through LLM configurations. With 8 critical CVEs including SQL injection and deserialization vulnerabilities, plus 81 high-priority issues heavily impacting WordPress ecosystems, security teams face immediate patching requirements.
Immediate action: IMMEDIATE: Patch TP-Link TL-WR841N (CVE-2023-50224) and TP-Link Multiple Routers (CVE-2025-9377) TODAY for federal compliance. Address Flowise RCE immediately if using LLM platforms.
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
Meta Platforms WhatsApp Incorrect Authorization Vulnerability - Active in CISA KEV catalog.
TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability - Active in CISA KEV catalog.
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability - Active in CISA KEV catalog.
Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability - Active in CISA KEV catalog.
Android Runtime Use-After-Free Vulnerability - Active in CISA KEV catalog.
Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
A SQL Injection vulnerability was discovered in the foreigner-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execut...
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input conf...
A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system files and execute arbitrary code. The vulnerability arises from improper handlin...
Airship AI Acropolis includes a default administrative account that uses the same credentials on every installation. Instances of Airship AI that do not change this account password are vulnerable to ...
The Blackmagic Web Presenter HD firmware version 3.3 exposes sensitive information via an unauthenticated Telnet service on port 9977. When connected, the service reveals extensive device configuratio...
The Blackmagic ATEM Mini Pro 2.7 exposes sensitive device and stream configuration information via an unauthenticated Telnet service on port 9990. Upon connection, the attacker can access a protocol p...
Cross-Site Request Forgery (CSRF) vulnerability in yonisink Custom Post Type Images allows Code Injection. This issue affects Custom Post Type Images: from n/a through 0.5.
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability in Flowise Cloud allows any user on t...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hashthemes Easy Elementor Addons allows PHP Local File Inclusion
Cross-Site Request Forgery (CSRF) vulnerability in wpdesk Flexible PDF Invoices for WooCommerce & WordPress allows Cross Site Request Forgery
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Pluginwale Easy Pricing Table WP allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in immonex immonex Kickstart Team allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad allows PHP Local File Inclusion
Cross-Site Request Forgery (CSRF) vulnerability in purethemes WorkScout-Core allows Cross Site Request Forgery
Deserialization of Untrusted Data vulnerability in ConveyThis Language Translate Widget for WordPress β ConveyThis allows Object Injection
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Sitecore Sitecore Experience Manager (XM), Sitecore Experience Platform (XP) allows Cross-Site Scripting (XSS)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows SQL Injection
Authlib is a Python library which builds OAuth and OpenID Connect servers
Cross-Site Request Forgery (CSRF) vulnerability in pebas CouponXxL allows Privilege Escalation
Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Authentication Bypass
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus@hotmail
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFunnels Mail Mint allows SQL Injection
A security flaw has been discovered in UTT HiPER 840G up to 3
A weakness has been identified in UTT 1200GW up to 3
A security flaw has been discovered in B-Link BL-AC2100 up to 1
A vulnerability was found in D-Link DCS-935L up to 1
A security vulnerability has been detected in D-Link DIR-513 A1FW110
A vulnerability has been found in Tenda AC23 up to 16
The Sound4 PULSE-ECO AES67 1
Creacast Creabox Manager contains a critical authentication flaw that allows an attacker to bypass login validation
In 2wcom IP-4c 2
Creacast Creabox Manager 4
Cross-Site Request Forgery (CSRF) vulnerability in Anps Constructo allows Object Injection
A vulnerability was identified in Tenda AC20 up to 16
Deserialization of Untrusted Data vulnerability in raoinfotech GSheets Connector allows Object Injection
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support allows Object Injection
Mesh Connect JS SDK contains JS libraries for integrating with Mesh Connect
The txtai framework allows the loading of compressed tar files as embedding indices
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2
A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerability
A flaw was found in the Lightspeed history service
Airship AI Acropolis allows unlimited MFA attempts for 15 minutes after a user has logged in with valid credentials
IBM webMethods Integration 10
Flowise is a drag & drop user interface to build a customized large language model flow
A vulnerability was identified in Campcodes Online Learning Management System 1
A security flaw has been discovered in Campcodes Online Learning Management System 1
A weakness has been identified in Campcodes Online Learning Management System 1
A security vulnerability has been detected in Campcodes Online Learning Management System 1
A vulnerability was detected in Campcodes Grocery Sales and Inventory System 1
A flaw has been found in Campcodes Grocery Sales and Inventory System 1
A vulnerability was determined in SourceCodester Online Hotel Reservation System 1
A vulnerability was identified in SourceCodester Online Hotel Reservation System 1
A weakness has been identified in code-projects Online Bidding System 1
A vulnerability was detected in code-projects E-Commerce Website 1
A vulnerability has been found in code-projects Online Bidding System 1
A vulnerability was found in code-projects Hostel Management System 1
A vulnerability was determined in code-projects Hostel Management System 1
A vulnerability was identified in code-projects Hostel Management System 1
A security flaw has been discovered in code-projects Hostel Management System 1
A weakness has been identified in itsourcecode Online Discussion Forum 1
A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1
A flaw has been found in code-projects Online Bidding System 1
A weakness has been identified in Campcodes Farm Management System 1
A security vulnerability has been detected in Campcodes Online Learning Management System 1
Cross-Site Scripting (XSS) vulnerability was discovered in the Ajax transaction manager endpoint of ARD
A vulnerability was detected in Campcodes Online Learning Management System 1
A flaw has been found in code-projects Hostel Management System 1
A vulnerability has been found in code-projects Hostel Management System 1
A vulnerability was found in code-projects Hostel Management System 1
A security flaw has been discovered in Jinher OA 2
A weakness has been identified in Campcodes Online Learning Management System 1
CubeCart is an ecommerce software solution
Cross-Site Request Forgery (CSRF) vulnerability in ERA404 LinkedInclude allows Stored XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikRestaurants Table Reservations and Take-Away allows Reflected XSS
Cross-Site Request Forgery (CSRF) vulnerability in scriptsbundle Nokri allows Cross Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in PressPage Entertainment Inc Mavis HTTPS to HTTP Redirection allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in wpdirectorykit Sweet Energy Efficiency allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in Aftabul Islam Stock Message allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in WPMK WPMK PDF Generator allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in NIX Solutions Ltd NIX Anti-Spam Light allows Cross Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in EdwardBock Grid allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in Shankaranand Maurya WP Content Protection allows Stored XSS
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in morganrichards Auction Feed allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in extendyourweb HORIZONTAL SLIDER allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in puravida1976 ShrinkTheWeb (STW) Website Previews allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in WP CMS Ninja Current Age Plugin allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in Casengo Casengo Live Chat Support allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in ptibogxiv Doliconnect allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in loopus WP Attractive Donations System allows Stored XSS