CVE-2025-12480
Gladinet Triofox Improper Access Control Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Tuesday's vulnerability disclosure reflects elevated activity with 8 critical CVEs and 57 high-priority vulnerabilities, representing a 300% increase in critical vulnerabilities compared to Monday. Three severe SQL injection vulnerabilities in Blood Bank Management System (CVSS 10.0, 9.6, 9.6) and privilege escalation in Avast Antivirus (CVSS 9.0) highlight the most severe threats. Six CISA KEV vulnerabilities continue to require remediation across Samsung Mobile, Gladinet Triofox, Microsoft Windows, WatchGuard Firebox, and Google Chromium systems.
Immediate action: Security teams should review the 8 critical vulnerabilities and assess organizational exposure to the 57 high-priority CVEs. Organizations should continue addressing the 6 CISA KEV vulnerabilities.
Gladinet Triofox Improper Access Control Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Race Condition Vulnerability - Active in CISA KEV catalog.
WatchGuard Firebox Out-of-Bounds Write Vulnerability - Active in CISA KEV catalog.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
OpenPLC ScadaBR Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and rpassword fields, an attacker can bypass authentication and gain unauthorized access to the system.
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.
A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an attacker can bypass authentication and gain unauthorized access to the system.
Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.
Heap-based Buffer Overflow, Out-of-bounds Read vulnerability in Avast Antivirus on MacOS when scanning a malformed file may allow Local Execution of Code or Denial-of-Service of the anitvirus engine process.This issue affects Antivirus: from 8.3.70.94 before 8.3.70.98.
An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection vulnerability in the cloneRepo method. The application passes the user-supplied githubUrl argument directly to a system shell via execSync without sanitization. This allows an attacker to execute arbitrary commands on the host machine by appending shell metacharacters to the URL.
Heap-based Buffer Overflow, Out-of-bounds Write vulnerability in Avast Antivirus on MacOS of a crafted Mach-O file may allow Local Execution of Code or Denial of Service of antivirus protection
NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash
SoftSea EPUB File Reader 1
Uncontrolled recursion in the json2pb component in Apache bRPC (version < 1
Denial of Service vulnerability in Apache Struts, file leak in multipart request processing causes disk exhaustion
A buffer overflow vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition
Frappe is a full-stack web application framework
Grav is a file-based Web platform
Grav is a file-based Web platform
Grav is a file-based Web platform
An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System 2
A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System within the abs
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1
A cross-site scripting (XSS) vulnerability exists in the Blood Bank Management System 1
Grav is a file-based Web platform
The service wmp-agent of KerOS prior 5
Incorrect access control in the SDAgent component of Shirt Pocket SuperDuper! v3
The installer of INZONE Hub 1
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system
An issue in Shirt Pocket SuperDuper! V
In nr modem, there is a possible system crash due to improper input validation
In nr modem, there is a possible system crash due to improper input validation
In nr modem, there is a possible system crash due to improper input validation
In dpc modem, there is a possible system crash due to null pointer dereference
In nr modem, there is a possible system crash due to improper input validation
In nr modem, there is a possible system crash due to improper input validation
In modem, there is a possible system crash due to improper input validation
In nr modem, there is a possible system crash due to improper input validation
In nr modem, there is a possible system crash due to improper input validation
In nr modem, there is a possible system crash due to improper input validation
In nr modem, there is a possible system crash due to improper input validation
An issue in Technitium through v13
A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1
A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665
A vulnerability has been found in Chanjet CRM up to 20251106
A security flaw has been discovered in Qualitor up to 8
A vulnerability was identified in MediaCrush 1
A security vulnerability has been detected in nutzam NutzBoot up to 2
A flaw has been found in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1
A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5
A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1
Tryton trytond 6
nopCommerce v4
vLLM is an inference and serving engine for large language models (LLMs)