CVE-2025-5086
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
This curated brief highlights 1 critical vulnerabilities and 39 high-priority updates requiring immediate attention.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
get-jwks contains fetch utils for JWKS keys. In versions prior to 11.0.2, a vulnerability in get-jwks can lead to cache poisoning in the JWKS key-fetching mechanism. When the iss (issuer) claim is val...
A weakness has been identified in PHPGurukul Small CRM 4
The llama-index-core package, up to version 0
The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User-Agent Header in all versions up to, and including, 14
WeGIA is a Web manager for charitable institutions
A security flaw has been discovered in Tenda AC21 up to 16
A vulnerability was determined in Tenda CH22 1
A weakness has been identified in Tenda AC8 16
A vulnerability was detected in Tenda AC18 15
A flaw has been found in Tenda AC18 15
Flag Forge is a Capture The Flag (CTF) platform
SysReptor is a fully customizable pentest reporting platform
Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11
A security flaw has been discovered in kidaze CourseSelectionSystem 1
A vulnerability was detected in SourceCodester Online Hotel Reservation System 1
A vulnerability has been found in SourceCodester Pet Grooming Management Software 1
A vulnerability was found in Campcodes Online Learning Management System 1
A vulnerability was determined in Campcodes Online Learning Management System 1
A vulnerability was identified in Campcodes Online Learning Management System 1
A security flaw has been discovered in Campcodes Online Learning Management System 1
A flaw has been found in code-projects Online Bidding System 1
A vulnerability was identified in Projectworlds Online Shopping System 1
A flaw has been found in code-projects Project Monitoring System 1
A vulnerability has been found in Campcodes Online Learning Management System 1
A vulnerability was found in Campcodes Online Learning Management System 1
A vulnerability was determined in Campcodes Online Learning Management System 1
A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464
A security vulnerability has been detected in code-projects E-Commerce Website 1
A security flaw has been discovered in itsourcecode Open Source Job Portal 1
A weakness has been identified in Campcodes Online Learning Management System 1
A flaw has been found in code-projects Simple Scheduling System 1
A vulnerability has been found in code-projects Simple Scheduling System 1
A vulnerability was found in code-projects Simple Scheduling System 1
A vulnerability was determined in code-projects Simple Scheduling System 1
A vulnerability was identified in Campcodes Computer Sales and Inventory System 1
A security flaw has been discovered in Campcodes Online Learning Management System 1
A weakness has been identified in Campcodes Advanced Online Voting Management System 1
A vulnerability has been found in code-projects Simple Scheduling System 1
A vulnerability was found in code-projects Simple Scheduling System 1
A vulnerability was identified in CodeAstro Student Grading System 1