CVE-2025-13223
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
Friday's vulnerability disclosure shows eight critical vulnerabilities and 47 high-priority CVEs, representing a significant decrease in critical activity from Thursday's elevated count of 28. Six actively exploited CISA KEV vulnerabilities continue to require remediation. The decrease in critical CVEs (from 28 to 8) reflects a return to more typical disclosure levels after Thursday's increased activity.
Immediate action: Security teams should review the eight critical vulnerabilities and continue addressing the 47 high-priority CVEs. Organizations should prioritize remediation of the six actively exploited CISA KEV vulnerabilities. Detailed analyst comments are available for select CVEs to support remediation planning.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability - Active in CISA KEV catalog.
OpenPLC ScadaBR Cross-site Scripting Vulnerability - Active in CISA KEV catalog.
Android Framework Information Disclosure Vulnerability - Active in CISA KEV catalog.
Android Framework Privilege Escalation Vulnerability - Active in CISA KEV catalog.
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.4.4 due to incorrect implementation of the authentication algorithm in the "wdk_generate_auto_login_link" function. This is due to the feature using a cryptographically weak token generation mechanism. This makes it possible for unauthenticated attackers to gain administrative access and achieve full site takeover via the auto-login endpoint with a predictable token.
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints.
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the prepare_form() function. This is due to the function accepting user input and then passing that through call_user_func_array(). This makes it possible for unauthenticated attackers to execute arbitrary code on the server, which can be leveraged to inject backdoors or create new administrative user accounts.
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in all versions up to, and including, 3.28.20. This is due to insufficient capability checks and input validation in the ActionOptions::run() save handler. This makes it possible for unauthenticated attackers to modify critical WordPress options such as users_can_register, default_role, and admin_email via submitting crafted form data to public frontend forms.
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criteria parameter. This input is subsequently evaluated by setDynamicContent, allowing an unauthenticated attacker to execute arbitrary code via the m tag. The vulnerability is patched in versions 7.2.8, 7.3.13, and 7.4.6.
DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.
Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.
In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to embed malicious JavaScript. The payload executes when an administrator clicks the image link to view the avatar, resulting in stored cross-site scripting (XSS). Successful exploitation may lead to account takeover, privilege escalation, or full compromise of the affected ERPNext instance.
A flaw was found in the ABRT daemon’s handling of user-supplied mount information
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the Machine
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the SMB server function
Masa CMS is an open source Enterprise Content Management platform
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path
A flaw was found in WebKitGTK
A weakness has been identified in H3C Magic B0 up to 100R002
The PostGallery plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'PostGalleryUploader' class functions in all versions up to, and including, 1
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline
A heap buffer overflow in compiler
Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances
In Splunk Enterprise for Windows versions below 10
In Splunk Universal Forwarder for Windows versions below 10
GZDoom is a feature centric port for all Doom engine games
Akamai Guardicore Platform Agent before 52
WebPros Plesk before 18
Coder allows organizations to provision remote development environments via Terraform
Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1
Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1
An Improper Input Validation vulnerability exists in the user websocket handler of MAAS
Aquarius Desktop 3
RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive interface
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'ajax_unzip_file' function in versions 2
Abacre Restaurant Point of Sale (POS) up to 15
Masa CMS is an open source Enterprise Content Management platform
An issue was discovered in Camera in Samsung Mobile Processor Exynos 1280 and 2200
A flaw was found in Undertow that can cause remote denial of service attacks
Untrusted search path in auth_query connection handler in PgBouncer before 1
NVIDIA Triton Inference Server contains a vulnerability where an attacker may cause an improper check for unusual or exceptional conditions issue by sending extra large payloads
NVIDIA Triton Server for Linux contains a vulnerability where an attacker may cause an improper validation of specified quantity in input
Out-of-bounds write vulnerability in cgi components in Synology DiskStation Manager (DSM) before 7
Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1
auth0/node-jws is a JSON Web Signature implementation for Node
There is a relative path traversal vulnerability in the NI System Web Server that may result in information disclosure
The password reset mechanism for the Pivot client application is weak, and it may allow an attacker to take over the account
Fulcio is a free-to-use certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity
Advantech iView versions 5
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps
A flaw was found in WebKitGTK
SysReptor is a fully customizable pentest reporting platform
The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'ajax_unzip_file' function in versions 2
The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sync() function in all versions up to, and including, 1
A vulnerability in portenable cgi allows remote authenticated users to get the status of installed packages
DCIM dcTrack allows an attacker to misuse certain remote access features
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files