CVE-2025-5086
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 3 critical vulnerabilities and 33 high-priority updates requiring immediate attention.
Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability - Active in CISA KEV catalog.
Libraesva Email Security Gateway Command Injection Vulnerability - Active in CISA KEV catalog.
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Adminer Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Fayton Software and Consulting Services fayton.Pro ERP allows SQL Injection.This issue affects fay...
A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects unknown code of the file /system/www/system.ini. The manipulation results in hard-coded credentials. The a...
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via im...
VMware Tools for Windows contains an improper authorisationΒ vulnerability due to the way it handles user access controls
VMware vCenter contains an SMTP header injection vulnerability
VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability
VMware NSX contains a weak password recovery mechanism vulnerability
Description: VMware NSX contains a username enumeration vulnerability
A weakness has been identified in iHongRen pptp-vpn 1
A security flaw has been discovered in Tenda AC21 up to 16
A vulnerability was determined in Tenda CH22 1
A weakness has been identified in Tenda AC8 16
A vulnerability was detected in Tenda AC18 15
A flaw has been found in Tenda AC18 15
In Progress Chef Automate, versions earlier than 4
Improper restriction of XML external entity reference issue exists in DataSpider Servista 4
A reflected cross-site scripting (XSS) vulnerability in tawk
Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user
An integer overflow vulnerability exists in the WebSocket component of Mongoose 7
A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464
A security vulnerability has been detected in code-projects E-Commerce Website 1
A security flaw has been discovered in itsourcecode Open Source Job Portal 1
A weakness has been identified in Campcodes Online Learning Management System 1
A flaw has been found in code-projects Simple Scheduling System 1
A vulnerability has been found in code-projects Simple Scheduling System 1
A vulnerability was found in code-projects Simple Scheduling System 1
A vulnerability was determined in code-projects Simple Scheduling System 1
A vulnerability was identified in Campcodes Computer Sales and Inventory System 1
A security flaw has been discovered in Campcodes Online Learning Management System 1
A weakness has been identified in Campcodes Advanced Online Voting Management System 1
A vulnerability has been found in code-projects Simple Scheduling System 1
A vulnerability was found in code-projects Simple Scheduling System 1
A vulnerability was identified in CodeAstro Student Grading System 1
A vulnerability was detected in pmTicket Project-Management-Software up to 2ef379da2075f4761a2c9029cf91d073474e7486
A vulnerability was identified in Bjskzy Zhiyou ERP up to 11
A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field