CVE-2025-58034
Fortinet FortiWeb OS Command Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 0 critical vulnerabilities and 19 high-priority updates requiring immediate attention.
Fortinet FortiWeb OS Command Injection Vulnerability - Active in CISA KEV catalog.
CWP Control Web Panel OS Command Injection Vulnerability - Active in CISA KEV catalog.
Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability - Active in CISA KEV catalog.
Samsung Mobile Devices Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Gladinet Triofox Improper Access Control Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Race Condition Vulnerability - Active in CISA KEV catalog.
WatchGuard Firebox Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1
The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1
A flaw has been found in D-Link DIR-822K and DWR-M920 1
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1
A vulnerability was found in D-Link DIR-822K 1
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1
A weakness has been identified in D-Link DWR-M920 1
A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution
Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution
A security vulnerability has been detected in Campcodes Supplier Management System 1
A vulnerability was detected in Campcodes School File Management System 1
A flaw has been found in Campcodes Online Polling System 1
A vulnerability has been found in Campcodes Online Polling System 1
A vulnerability was found in SourceCodester Company Website CMS 1
A vulnerability was determined in SourceCodester Company Website CMS 1
A vulnerability was identified in D-Link DIR-852 1
A vulnerability was identified in projectworlds Advanced Library Management System 1