CVE-2025-13223
Google Chromium V8 Type Confusion Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
Monday's vulnerability disclosure reveals two newly published critical vulnerabilities and 17 high-priority CVEs as security teams return to the work week. Seven actively exploited CISA KEV vulnerabilities continue to require remediation. The overall critical CVE frequency shows an 83% decrease compared to historical averages, maintaining the reduced disclosure activity observed over the weekend period.
Immediate action: Security teams should assess the two newly published critical vulnerabilities and review the 17 high-priority CVEs. Organizations should prioritize remediation of the seven actively exploited CISA KEV vulnerabilities.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.