CVE-2025-41244
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Tuesday's security landscape reveals a significant escalation in vulnerability disclosures following Monday's quiet period, with 4 new critical vulnerabilities requiring immediate attention. The WordPress W3 Total Cache plugin command injection vulnerability (CVE-2025-9501, CVSS 9.0) poses the most immediate threat to organizations, allowing unauthenticated attackers to execute arbitrary commands through malicious comment submissions. High-priority vulnerabilities surged 240% from 15 to 51 issues, while patch availability remains critically low at 7%, requiring organizations to implement compensating controls. Nine actively exploited CISA KEV vulnerabilities continue to demand priority remediation across VMware, Fortinet, and Microsoft products.
Immediate action: Security teams must immediately update WordPress W3 Total Cache to version 2.8.13 or later and review web server logs for comment submission exploitation attempts. Organizations with limited patch availability should deploy Web Application Firewalls with command injection and SQL injection detection rules. Priority remediation of the nine active CISA KEV vulnerabilities should continue while monitoring for the four new critical disclosures. All affected systems should be treated as potentially compromised until verified secure through log analysis and system integrity checks.
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability - Active in CISA KEV catalog.
XWiki Platform Eval Injection Vulnerability - Active in CISA KEV catalog.
Fortinet FortiWeb Path Traversal Vulnerability - Active in CISA KEV catalog.
CWP Control Web Panel OS Command Injection Vulnerability - Active in CISA KEV catalog.
Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability - Active in CISA KEV catalog.
Samsung Mobile Devices Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Gladinet Triofox Improper Access Control Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Race Condition Vulnerability - Active in CISA KEV catalog.
WatchGuard Firebox Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.
PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.
QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the login page can gain administrative access.
phpMyFAQ is an open source FAQ web application
The Booking for Appointments and Events Calendar â Amelia plugin for WordPress is vulnerable to SQL Injection via the âsearchâ parameter in all versions up to, and including, 1
A security flaw has been discovered in PHPGurukul Tourism Management System 1
A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5
A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5
A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5
A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5
An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with valid API tokens to inject SQL via crafted input
EasyFlow GP developed by Digiwin has a Denial of service vulnerability, allowing unauthenticated remote attackers to send specific requests that result in denial of web service
Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU race condition and trigger a read and/or write of data outside the allotted memory escaping the virtual machine
A vulnerability was detected in Tenda AC20 up to 16
A security vulnerability has been detected in Tenda CH22 1
QaTraq 6
A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1
A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Delete vulnerability
MyScreenTools v2
IBM Planning Analytics Local 2
A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29
OpenStack Keystone before 26
Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to memory buffers exported as read-only
Glob matches files using patterns the shell uses
IBM Storage Virtualize 8
A vulnerability has been found in itsourcecode Inventory Management System 1
A vulnerability was determined in itsourcecode Inventory Management System 1
A security flaw has been discovered in itsourcecode Inventory Management System 1
A vulnerability was detected in code-projects Student Information System 2
A flaw has been found in code-projects Student Information System 2
A vulnerability has been found in code-projects Student Information System 2
A weakness has been identified in SourceCodester Patients Waiting Area Queue Management System 1
A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a
A security vulnerability has been detected in itsourcecode Inventory Management System 1
A vulnerability was determined in lsfusion platform up to 6
A vulnerability was determined in Campcodes School Fees Payment Management System 1
A vulnerability was identified in Campcodes School Fees Payment Management System 1
A vulnerability was detected in g33kyrash Online-Banking-System up to 12dbfa690e5af649fb72d2e5d3674e88d6743455
A flaw has been found in code-projects Nero Social Networking Site 1
A vulnerability was determined in CodeAstro Simple Inventory System 1
A vulnerability was identified in itsourcecode Online Voting System 1
A vulnerability was found in Campcodes Supplier Management System 1
A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1
A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1
A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1
A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1
A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1
TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability
PDFPatcher thru 1