CVE-2009-0556
Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's disclosures contained zero critical-severity CVEs, a significant decrease from the prior day's two critical vulnerabilities. High-priority vulnerabilities dropped 60% to 21 entries compared to 53 previously. Four actively exploited vulnerabilities were added to the KEV catalog, including CVE-2009-0556 affecting Microsoft Office, CVE-2025-37164 in HPE OneView, CVE-2025-8110 targeting Gogs, and CVE-2026-20805 impacting Microsoft Windows. All four KEV entries carry CVSS scores of 9.5, indicating severe impact potential despite the absence of newly disclosed critical CVEs. Patch availability stands at 0%, indicating these vulnerabilities currently lack vendor-supplied fixes.
Immediate action: Organizations running Microsoft Office, Microsoft Windows, HPE OneView, or Gogs should prioritize reviewing these actively exploited vulnerabilities for potential exposure. With no patches currently available, implement compensating controls such as network segmentation, access restrictions, and enhanced monitoring for affected systems.
Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability - Active in CISA KEV catalog.
Gogs Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Information Disclosure Vulnerability - Active in CISA KEV catalog.
Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system
A vulnerability was detected in UTT θΏε 520W 1
A flaw has been found in UTT θΏε 520W 1
A vulnerability has been found in UTT θΏε 520W 1
A vulnerability was found in UTT θΏε 520W 1
A weakness has been identified in TOTOLINK A3700R 9
A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9
A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa
A vulnerability was identified in EasyCMS up to 1
A flaw has been found in itsourcecode Society Management System 1
A vulnerability has been found in Yonyou KSOA 9
A vulnerability was found in Yonyou KSOA 9
A vulnerability was determined in Yonyou KSOA 9
A vulnerability was identified in Yonyou KSOA 9
A security flaw has been discovered in Yonyou KSOA 9
A weakness has been identified in D-Link DIR-823X 250416
A vulnerability was detected in Yonyou KSOA 9
A flaw has been found in Yonyou KSOA 9
A vulnerability has been found in Yonyou KSOA 9
A vulnerability was found in Yonyou KSOA 9
A vulnerability was determined in Yonyou KSOA 9