CVE-2025-13223
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
This curated brief highlights 7 critical vulnerabilities and 64 high-priority updates requiring immediate attention.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
OpenPLC ScadaBR Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Android Framework Information Disclosure Vulnerability - Active in CISA KEV catalog.
Android Framework Privilege Escalation Vulnerability - Active in CISA KEV catalog.
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.
In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6.
In Splunk Enterprise for Windows versions below 10
In Splunk Universal Forwarder for Windows versions below 10
The SureMail â SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type in versions up to and including 1
Use after free in Digital Credentials in Google Chrome prior to 143
Use after free in Media Stream in Google Chrome prior to 143
The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer name in all versions up to, and including, 1
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'month' parameter in all versions up to, and including, 1
The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the deleteOrdersFiles() function in all versions up to, and including, 3
Type Confusion in V8 in Google Chrome prior to 143
Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143
Bad cast in Loader in Google Chrome prior to 143
Akamai Guardicore Platform Agent before 52
The db-access WordPress plugin through 0
Race in v8 in Google Chrome prior to 143
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2
Coder allows organizations to provision remote development environments via Terraform
A flaw was found in Undertow that can cause remote denial of service attacks
A heap buffer overflow in compiler
Improper access control in MPRemoteService of MotionPhoto prior to version 4
Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9
A flaw was found in the ABRT daemonâs handling of user-supplied mount information
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function
Masa CMS is an open source Enterprise Content Management platform
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path
IBM Informix Dynamic Server 14
NMIS/BioDose V22
NMIS/BioDose V22
NMIS/BioDose V22
NMIS/BioDose V22
GZDoom is a feature centric port for all Doom engine games
In mmdvfs, there is a possible out of bounds write due to a missing bounds check
In smi, there is a possible out of bounds write due to a missing bounds check
In display, there is a possible memory corruption due to improper input validation
In display, there is a possible out of bounds write due to an integer overflow
In display, there is a possible out of bounds read due to a missing bounds check
Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9
Vim is an open source, command line text editor
WebPros Plesk before 18
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS
Aquarius Desktop 3
The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface
Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9
Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304
User Enumeration Vulnerability in TCMAN GIM v11 version 20250304
An issue was discovered in 5
EverShop 2
Within HostnameError
Abacre Restaurant Point of Sale (POS) up to 15
Masa CMS is an open source Enterprise Content Management platform
An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200
Untrusted search path in auth_query connection handler in PgBouncer before 1
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads
NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input
A flaw was found in WebKitGTK
Improper access control in MPLocalService of MotionPhoto prior to version 4
NMIS/BioDose software V22
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13
Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files