CVE-2009-0556
Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's disclosures included 2 critical CVEs, a 92% decrease from the prior day's 26 critical vulnerabilities. High-priority vulnerabilities also declined significantly, with 39 CVEs compared to 100 the previous day, representing a 61% reduction. Ten actively exploited vulnerabilities remain on CISA's KEV catalog, affecting Microsoft Windows, Microsoft Office, Cisco Unified Communications Manager, HPE OneView, VMware vCenter Server, and Zimbra Collaboration Suite. Notable critical disclosures include CVE-2025-13374 (CVSS 9.8), an arbitrary file upload vulnerability in the Kalrav AI Agent WordPress plugin, and CVE-2026-24399 (CVSS 9.3) affecting ChatterMate. Patch availability stands at 0%, requiring organizations to implement compensating controls until vendor fixes are released.
Immediate action: Organizations running Microsoft Windows, Cisco Unified Communications Manager, HPE OneView, VMware vCenter Server, or Zimbra should prioritize reviewing the actively exploited CVEs and implement available mitigations. With no patches currently available for newly disclosed critical vulnerabilities, focus on network segmentation and monitoring for exploitation attempts.
Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability - Active in CISA KEV catalog.
Gogs Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Information Disclosure Vulnerability - Active in CISA KEV catalog.
Cisco Unified Communications Products Code Injection Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability - Active in CISA KEV catalog.
Versa Concerto Improper Authentication Vulnerability - Active in CISA KEV catalog.
Vite Vitejs Improper Access Control Vulnerability - Active in CISA KEV catalog.
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability - Active in CISA KEV catalog.
The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malicious HTML/JavaScript payloads when supplied as chat input. Specifically, an <iframe> payload containing a javascript: URI can be processed and executed in the browser context. This allows access to sensitive client-side data such as localStorage tokens and cookies, resulting in client-side injection. This issue has been fixed in version 1.0.9.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent Core laurent-core allows PHP Local File Inclusion
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in DevsBlink EduBlink Core edublink-core allows PHP Local File Inclusion
The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Laurent laurent allows PHP Local File Inclusion
The User Submitted Posts â Enable Users to Submit Posts from the Front End plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom fields in all versions up to, and including, 20251210 due to insufficient input sanitization and output escaping
An unauthenticated information disclosure vulnerability in Newgen OmniApp allows attackers to enumerate valid privileged usernames via a publicly accessible client-side JavaScript resource
The Administrative Shortcodes plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0
The Hustle â Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the action_import_module() function in all versions up to, and including, 7
The Frontis Blocks plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1
Dell ECS, versions 3
LiteSpeed Web Server Enterprise 5
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nelio Software Nelio Content nelio-content allows Blind SQL Injection
An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/GetListofCabinet API endpoint
Textpattern versions prior to 4
PhreeBooks 5
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in saeros1984 Neoforum neoforum allows Blind SQL Injection
dataSIMS Avionics ARINC 664-1 version 4
Softros LAN Messenger 9
LogonExpert 8
PDF Complete Corporate Edition 4
Epson USB Display 1
Null pointer dereference in free5gc pcf 1
AgataSoft PingMaster Pro 2
Managed Switch Port Mapping Tool 2
Nsauditor 3
Incorrect access control in the selectDept function of RuoYi v4
C++ HTTP Server is an HTTP/1
PEEL Shopping 9
PEEL Shopping 9
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles
iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles