CVE-2025-58034
Fortinet FortiWeb OS Command Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
This curated brief highlights 0 critical vulnerabilities and 19 high-priority updates requiring immediate attention.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Fortinet FortiWeb OS Command Injection Vulnerability - Active in CISA KEV catalog.
CWP Control Web Panel OS Command Injection Vulnerability - Active in CISA KEV catalog.
Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability - Active in CISA KEV catalog.
Samsung Mobile Devices Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Gladinet Triofox Improper Access Control Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Race Condition Vulnerability - Active in CISA KEV catalog.
WatchGuard Firebox Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1
The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1
A flaw has been found in D-Link DIR-822K and DWR-M920 1
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1
A vulnerability was found in D-Link DIR-822K 1
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1
A weakness has been identified in D-Link DWR-M920 1
A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution
Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution
A security vulnerability has been detected in Campcodes Supplier Management System 1
A vulnerability was detected in Campcodes School File Management System 1
A flaw has been found in Campcodes Online Polling System 1
A vulnerability has been found in Campcodes Online Polling System 1
A vulnerability was found in SourceCodester Company Website CMS 1
A vulnerability was determined in SourceCodester Company Website CMS 1
A vulnerability was identified in D-Link DIR-852 1
A vulnerability was identified in projectworlds Advanced Library Management System 1