CVE-2014-6278
GNU Bash OS Command Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's security landscape reveals a dramatic post-weekend lull with only 2 critical vulnerabilities (CVSS 9.0+), representing an 86% decrease from the historical average. The newly disclosed CVE-2025-11948 (Document Management System arbitrary file upload) and CVE-2025-61932 (Lanscope Endpoint Manager RCE) both scored CVSS 9.8 and allow unauthenticated remote code execution, presenting immediate threats to enterprise infrastructure. Despite the reduced volume, organizations face 20 actively exploited CISA KEV vulnerabilities with 5 urgent federal deadlines expiring October 22 (3 days), including critical flaws in GNU Bash, Jenkins, Juniper ScreenOS, Samsung Mobile, and Smartbedded Meteobridge. Patch availability improved to 100% for today's critical vulnerabilities, though the federal compliance window for KEV remediation is rapidly closing heading into the midweek deadline.
Immediate action: Immediate action: Deploy emergency patches for CVE-2025-11948 (Document Management System) and CVE-2025-61932 (Lanscope Endpoint Manager) to prevent unauthenticated remote code execution. Prioritize CISA KEV remediation with 5 vulnerabilities reaching federal deadline October 22 (GNU Bash CVE-2014-6278, Jenkins CVE-2017-1000353, Juniper ScreenOS CVE-2015-7755, Samsung Mobile CVE-2025-21043, Smartbedded Meteobridge CVE-2025-4008). Organizations have 3 days to achieve KEV compliance before federal deadline expires.
GNU Bash OS Command Injection Vulnerability - Active in CISA KEV catalog.
Jenkins Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Juniper ScreenOS Improper Authentication Vulnerability - Active in CISA KEV catalog.
Samsung Mobile Devices Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Smartbedded Meteobridge Command Injection Vulnerability - Active in CISA KEV catalog.
Linux Kernel Heap Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Privilege Escalation Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Mozilla Multiple Products Remote Code Execution Vulnerability - Active in CISA KEV catalog.
Oracle E-Business Suite Unspecified Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Grafana Path Traversal Vulnerability - Active in CISA KEV catalog.
IGEL OS Use of a Key Past its Expiration Date Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Untrusted Pointer Dereference Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Improper Access Control Vulnerability - Active in CISA KEV catalog.
Rapid7 Velociraptor Incorrect Default Permissions Vulnerability - Active in CISA KEV catalog.
SKYSEA Client View Improper Authentication Vulnerability - Active in CISA KEV catalog.
Adobe Experience Manager Forms Code Execution Vulnerability - Active in CISA KEV catalog.
Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabl...
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending sp...
ETERNUS SF provided by Fsas Technologies Inc
A flaw has been found in 70mai X200 up to 20251010
A vulnerability has been found in 70mai X200 up to 20251010
A security vulnerability has been detected in LibreWolf up to 143