CVE-2025-14611
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's vulnerability disclosures included 1 critical CVE (CVSS 9.0+), a 67% decrease from the prior day's 3 critical issues. High-priority vulnerabilities totaled 30, representing a 33% reduction from 45. Five actively exploited vulnerabilities remain on the CISA KEV list, affecting Gladinet CentreStack/Triofox, Apple products, ASUS Live Update, Digiever DS-2105 Pro, and MongoDB Server. The single new critical vulnerability CVE-2025-14998 (CVSS 9.8) affects the Branda WordPress plugin through a privilege escalation flaw enabling account takeover. Patch availability stands at 0%, requiring organizations to implement compensating controls until vendor fixes become available.
Immediate action: Organizations running Gladinet CentreStack/Triofox, Apple products, ASUS systems with Live Update, Digiever DS-2105 Pro, or MongoDB Server should prioritize monitoring for exploitation indicators on these actively targeted platforms. With 0% patch availability for yesterday's disclosures, implement network segmentation and access controls as interim mitigations while monitoring vendor security advisories.
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability - Active in CISA KEV catalog.
Apple Multiple Products Use-After-Free WebKit Vulnerability - Active in CISA KEV catalog.
ASUS Live Update Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
Digiever DS-2105 Pro Missing Authorization Vulnerability - Active in CISA KEV catalog.
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability - Active in CISA KEV catalog.
The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.24. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
MessagePack for Java is a serializer implementation for Java
A security flaw has been discovered in Seeyon Zhiyuan OA Web Application System up to 20251222
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
A weakness has been identified in UTT čŋå 512W 1
A security vulnerability has been detected in UTT čŋå 512W 1
A vulnerability was detected in UTT čŋå 512W 1
A flaw has been found in UTT čŋå 512W 1
Plex Media Server (PMS) through 1
Emlog is an open source website building system
Signal K Server is a server application that runs on a central hub in a boat
A vulnerability has been found in code-projects Online Guitar Store 1
A vulnerability was found in code-projects Online Guitar Store 1
A vulnerability was determined in code-projects Online Guitar Store 1
A vulnerability was identified in code-projects Online Guitar Store 1
A security vulnerability has been detected in Yonyou KSOA 9
A vulnerability was detected in Yonyou KSOA 9
A vulnerability was found in Yonyou KSOA 9
A vulnerability was determined in Yonyou KSOA 9
A vulnerability was identified in jackying H-ui
A vulnerability was detected in Yonyou KSOA 9
A flaw has been found in Yonyou KSOA 9
A vulnerability has been found in Yonyou KSOA 9
A vulnerability was determined in code-projects Content Management System 1
A weakness has been identified in code-projects Content Management System 1
A vulnerability was detected in code-projects Content Management System 1
A flaw has been found in code-projects Online Music Site 1
A vulnerability has been found in code-projects Online Music Site 1
A vulnerability was found in code-projects Online Music Site 1
In Plex Media Server (PMS) through 1
Bagisto is an open source laravel eCommerce platform