CVE-2025-27915
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 5 critical vulnerabilities and 69 high-priority updates requiring immediate attention.
Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Grafana Path Traversal Vulnerability - Active in CISA KEV catalog.
IGEL OS Use of a Key Past its Expiration Date Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Untrusted Pointer Dereference Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Improper Access Control Vulnerability - Active in CISA KEV catalog.
SKYSEA Client View Improper Authentication Vulnerability - Active in CISA KEV catalog.
Adobe Experience Manager Forms Code Execution Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Unspecified Vulnerability - Active in CISA KEV catalog.
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
Microsoft Windows SMB Client Improper Access Control Vulnerability - Active in CISA KEV catalog.
Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability - Active in CISA KEV catalog.
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability - Active in CISA KEV catalog.
Adobe Commerce andâ¯Magento Improper Input Validation Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability - Active in CISA KEV catalog.
An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unauthorized attackers to access specific routes and modify database connection confi...
An issue in MikroTik RouterOS v.7.14.2 and SwitchOS v.2.18 allows a remote attacker to execute arbitrary code via the HTTP- only WebFig management component
Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Remote Code Inclusion.This issue affects Paid Videochat Turn...
Landlord Onboarding & Rental Signup introduces the landlord onboarding workflow and rental signup system for VivaTurbo Rentals & Property Services. In 2.0.0 and earlier, a vulnerability was identified...
The device is running an outdated operating system, which may be susceptible to known vulnerabilities.
Nagios Fusion v2024R1
indieka900 online-shopping-system-php 1
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1
HYDRA X, MIP 2 and FEDRA 2 of MPDV Mikrolab GmbH suffer from an unauthenticated local file disclosure vulnerability in all releases until Maintenance Pack 36Â with Servicepack 8 (week 36/2025), which allows an attacker to read arbitrary files from the Windows operating system
Relative Path Traversal vulnerability in Apache Tomcat
A security vulnerability has been detected in CLTPHP 3
A flaw has been found in Abdullah-Hasan-Sajjad Online-School up to f09dda77b4c29aa083ff57f4b1eb991b98b68883
A vulnerability has been found in dnsmasq up to 2
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services
Cross-Site Request Forgery (CSRF) vulnerability in Clifton Griffin Simple Content Templates for Blog Posts & Pages simple-post-template allows Cross Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in Andrea Landonio CloudSearch cloud-search allows Stored XSS
Missing Authorization vulnerability in MDZ Persian Admnin Fonts persian-admin-fonts allows Exploiting Incorrectly Configured Access Control Security Levels
A vulnerability was determined in Tenda O3 1
A vulnerability was identified in Tenda O3 1
A security flaw has been discovered in Tenda O3 1
A weakness has been identified in Tenda O3 1
A security vulnerability has been detected in Tenda O3 1
A vulnerability was detected in Tenda O3 1
A vulnerability has been found in Tenda AC6 15
A vulnerability was detected in Tenda CH22 1
A flaw has been found in Tenda CH22 1
A vulnerability has been found in Tenda CH22 1
A vulnerability was determined in Tenda CH22 1
A weakness has been identified in TOTOLINK A3300R 17
A security vulnerability has been detected in TOTOLINK A3300R 17
A vulnerability was detected in TOTOLINK A3300R 17
A vulnerability was detected in TOTOLINK A3300R 17
A flaw has been found in TOTOLINK A3300R 17
A vulnerability has been found in TOTOLINK A3300R 17
A weakness has been identified in Tenda CH22 1
A vulnerability was identified in Tenda CH22 1
A security flaw has been discovered in Tenda CH22 1
A weakness has been identified in Tenda CH22 1
A security vulnerability has been detected in Tenda CH22 1
A flaw has been found in Tenda CH22 1
A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite store implementation
TRUfusion Enterprise through 7
Incorrect Default Permissions vulnerability in Centreon Infra Monitoring (MBI modules) allows Embedding Scripts within Scripts by CentreonBI user account on the MBI server This issue affects Infra Monitoring: from 24
Pi-hole Admin Interface is a web interface for managing Pi-hole, a network-level advertisement and internet tracker blocking application
Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorrectly Configured Access Control Security Levels
A vulnerability was found in Tenda CH22 1
An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1
IBM QRadar SIEM 7
A private key disclosure vulnerability exists in ZTE's ZXMP M721 product
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11
The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access
StarCharge Artemis AC Charger 7-22 kW v1
TRUfusion Enterprise through 7
A vulnerability was found in SourceCodester Best House Rental Management System 1
A flaw has been found in projectworlds Online Shopping System 1
A vulnerability was identified in projectworlds Advanced Library Management System 1
A vulnerability was determined in AMTT Hotel Broadband Operation System 1
A security vulnerability has been detected in SourceCodester Online Student Result System 1
A vulnerability was determined in SourceCodester Point of Sales 1
A vulnerability was identified in SourceCodester Point of Sales 1
A security vulnerability has been detected in code-projects Simple Food Ordering System 1
A vulnerability was determined in code-projects Nero Social Networking Site 1
A vulnerability was identified in code-projects Nero Social Networking Site 1
A security flaw has been discovered in code-projects Nero Social Networking Site 1
A weakness has been identified in code-projects Nero Social Networking Site 1
A vulnerability was identified in code-projects Courier Management System 1
A vulnerability has been found in SourceCodester Best Salon Management System 1
A vulnerability was found in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5
Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incorrectly Configured Access Control Security Levels
Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v
Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS
A weakness has been identified in Hasleo Backup Suite up to 5
A weakness has been identified in VeePN up to 1