CVE-2025-10585
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 12 critical vulnerabilities and 82 high-priority updates requiring immediate attention.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability - Active in CISA KEV catalog.
Libraesva Email Security Gateway Command Injection Vulnerability - Active in CISA KEV catalog.
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Adminer Server-Side Request Forgery Vulnerability - Active in CISA KEV catalog.
GNU Bash OS Command Injection Vulnerability - Active in CISA KEV catalog.
Jenkins Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Juniper ScreenOS Improper Authentication Vulnerability - Active in CISA KEV catalog.
Samsung Mobile Devices Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Smartbedded Meteobridge Command Injection Vulnerability - Active in CISA KEV catalog.
Linux Kernel Heap Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Privilege Escalation Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Mozilla Multiple Products Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Oracle E-Business Suite Unspecified Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.
IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attack...
IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root d...
A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL commands via vulnerable input fields, enabling the execution ...
Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/api/admin/badge-templates/create` (POST) endpoints p...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection.This iss...
Improper Resource Locking vulnerability in B&R Industrial Automation Automation Runtime.This issue affects Automation Runtime: from 6.0 before 6.3, before Q4.93.
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain es...
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior...
The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorrect access control implementation in whitelist management fun...
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain es...
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain es...
The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
Improper Link Resolution Before File Access in the AWS VPN Client for macOS versions 1
Nagios Log Server before 2024R1
A vulnerability was identified in PHPGurukul Beauty Parlour Management System 1
A security flaw has been discovered in PHPGurukul Beauty Parlour Management System 1
IBM Security Verify Access and IBM Security Verify Access Docker 10
Rack is a modular Ruby web server interface
Rack is a modular Ruby web server interface
Rack is a modular Ruby web server interface
Dell PowerProtect Data Domain BoostFS for Linux Ubuntu systems of Feature Release versions 7
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7
IBM Security Verify Access and IBM Security Verify Access Docker 10
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1
Litestar is an Asynchronous Server Gateway Interface (ASGI) framework
IBM InfoSphere Data Replication VSAM for z/OS Remote Source 11
A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter
An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1
A vulnerability was determined in UTT 1250GW up to v2v3
A vulnerability was identified in Tenda AC18 15
A security flaw has been discovered in Tenda AC18 15
A weakness has been identified in Tenda AC18 15
A security vulnerability has been detected in Tenda AC18 15
A vulnerability was detected in Tenda AC18 15
A flaw has been found in D-Link DI-7100G C1 up to 20250928
A vulnerability has been found in D-Link DI-7100G C1 up to 20250928
A vulnerability has been found in UTT 1250GW up to v2v3
A vulnerability was found in Tenda AC23 up to 16
A vulnerability has been found in Tenda AC20 up to 16
A vulnerability was found in Tenda AC15 15
A vulnerability was determined in Tenda AC15 15
A vulnerability was identified in Tenda AC15 15
A security flaw has been discovered in Tenda AC15 15
A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1
A security vulnerability has been detected in D-Link DI-7001 MINI 24
Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload
Flowise is a drag & drop user interface to build a customized large language model flow
Flowise before 3
Flowise before 3
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4
An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being properly enforced for users with limited privileges
A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input parameters
Cross Site Request Forgery (CSRF) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM
A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing validation of an input parameter
The installers of DENSO TEN drive recorder viewer contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries
LLaMA-Factory is a tuning library for large language models
The HTMLSectionSplitter class in langchain-text-splitters version 0
Versions of the package pdfmake before 0
vLLM is an inference and serving engine for large language models (LLMs)
The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN)
A weakness has been identified in Tipray 厦门天锐科技股份有���公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A security vulnerability has been detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A vulnerability was detected in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A flaw has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A vulnerability has been found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A vulnerability was found in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A vulnerability was determined in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A vulnerability was identified in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A security flaw has been discovered in Tipray 厦门天锐科技股份有限公司 Data Leakage Prevention System 天锐数据泄露防护系统 1
A flaw has been found in code-projects Online Course Registration 1
A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1
A security flaw has been discovered in Jinher OA up to 2
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4
Cross Site Scripting (XSS) vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0076-000 Ver 4
A security vulnerability has been detected in code-projects Student Crud Operation 3
A vulnerability was found in code-projects Student Crud Operation up to 3
A vulnerability was determined in Campcodes Online Apartment Visitor Management System 1
A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1
A security flaw has been discovered in Campcodes Online Apartment Visitor Management System 1
A vulnerability was identified in code-projects Simple Food Ordering System 1
A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1
A Server-Side Request Forgery (SSRF) vulnerability exists in the MediaConnector class within the vLLM project's multimodal feature set