Critical vulnerabilities, curated daily for security professionals
đ¯ SSCV Profile
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Risk scores will be adjusted based on your selected environment
đ
Archived Security Brief
Yesterday's disclosures contained zero critical-severity CVEs, a complete decrease from the prior day's single critical vulnerability. High-priority vulnerabilities dropped significantly to 14 from 30, representing a 53% reduction in disclosure volume. Five actively exploited vulnerabilities remain on the CISA KEV list, affecting Gladinet CentreStack and Triofox, Apple products, ASUS Live Update, Digiever DS-2105 Pro, and MongoDB Server. The KEV entries include CVE-2025-14611 targeting Gladinet file collaboration platforms, CVE-2025-43529 impacting multiple Apple products, and CVE-2025-59374 affecting ASUS firmware update mechanisms. Current patch availability stands at 0%, indicating defensive measures should prioritize network segmentation and access controls until vendor patches become available.
Zero critical CVEs disclosed, down from 1 the prior day (-100%)
14 high-priority vulnerabilities, reduced from 30 (-53%)
Immediate action: Organizations using Gladinet CentreStack/Triofox, Apple products, ASUS systems with Live Update, Digiever NVR devices, or MongoDB deployments should review exposure immediately. With no patches currently available, implement compensating controls including network isolation, enhanced monitoring, and access restrictions for affected systems.
đĄ Tip: Swipe CVE cards left to â star, right to â remove
Section Navigation
â ī¸
CISA Known Exploited Vulnerabilities
â ī¸ CISA KEVURGENT
CVE-2025-14611
9.5
GladinetCentreStack and Triofox
â° Federal Deadline:January 4, 2026(1 days remaining)
Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2025-43529
9.5đ
AppleMultiple Products
â° Federal Deadline:January 4, 2026(1 days remaining)
Apple Multiple Products Use-After-Free WebKit Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEVURGENT
CVE-2025-59374
9.5
ASUSLive Update
â° Federal Deadline:January 6, 2026(3 days remaining)
ASUS Live Update Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2023-52163 (reserved 2023, disclosed 2025)
9.5
DigieverDS-2105 Pro
â° Federal Deadline:January 11, 2026(8 days remaining)
Digiever DS-2105 Pro Missing Authorization Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸ CISA KEV
CVE-2025-14847
9.5
MongoDBMongoDB and MongoDB Server
â° Federal Deadline:January 18, 2026(15 days remaining)
MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability - Active in CISA KEV catalog.
CVSS Base9.5
â
CRSSelect profile
â ī¸
High Priority Updates
CVE-2026-21452
7.5đ
MessagePackMultiple Products
MessagePack for Java is a serializer implementation for Java
CVSS Base7.5
â
CRSSelect profile
CVE-2025-69414 (reserved 2025, disclosed 2026)
8.5đ
MediaMultiple Products
Plex Media Server (PMS) through 1
CVSS Base8.5
â
CRSSelect profile
CVE-2026-21433
7.7đ
EmlogMultiple Products
Emlog is an open source website building system
CVSS Base7.7
â
CRSSelect profile
CVE-2026-0565
7.3đ
ManagementMultiple Products
A weakness has been identified in code-projects Content Management System 1
CVSS Base7.3
â
CRSSelect profile
CVE-2026-0567
7.3đ
ManagementMultiple Products
A vulnerability was detected in code-projects Content Management System 1
CVSS Base7.3
â
CRSSelect profile
CVE-2026-0568
7.3đ
MusicMultiple Products
A flaw has been found in code-projects Online Music Site 1
CVSS Base7.3
â
CRSSelect profile
CVE-2026-0569
7.3đ
MusicMultiple Products
A vulnerability has been found in code-projects Online Music Site 1
CVSS Base7.3
â
CRSSelect profile
CVE-2026-0570
7.3đ
MusicMultiple Products
A vulnerability was found in code-projects Online Music Site 1
CVSS Base7.3
â
CRSSelect profile
CVE-2025-3646 (reserved 2025, disclosed 2026)
7.3đ
PetlibroMultiple Products
Petlibro Smart Pet Feeder Platform versions up to 1
CVSS Base7.3
â
CRSSelect profile
CVE-2025-3653 (reserved 2025, disclosed 2026)
7.3đ
PetlibroMultiple Products
Petlibro Smart Pet Feeder Platform versions up to 1
CVSS Base7.3
â
CRSSelect profile
CVE-2026-0575
7.3đ
ReservationMultiple Products
A security vulnerability has been detected in code-projects Online Product Reservation System 1
CVSS Base7.3
â
CRSSelect profile
CVE-2026-0576
7.3đ
ReservationMultiple Products
A vulnerability was detected in code-projects Online Product Reservation System 1
CVSS Base7.3
â
CRSSelect profile
CVE-2025-69415 (reserved 2025, disclosed 2026)
7.1đ
MediaMultiple Products
In Plex Media Server (PMS) through 1
CVSS Base7.1
â
CRSSelect profile
CVE-2026-21447
7.1đ
BagistoMultiple Products
Bagisto is an open source laravel eCommerce platform