CVE-2009-0556
Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Tuesday's brief covers 3 critical CVEs (CVSS 9.0+), a notable increase from zero critical disclosures the prior day. High-priority vulnerabilities rose 218% to 35 CVEs compared to 11 previously. The CISA KEV catalog added 15 actively exploited vulnerabilities, including CVE-2026-20805 affecting Microsoft Windows, CVE-2025-37164 in HPE OneView, and CVE-2026-20045 targeting Cisco Unified Communications Manager. Critical disclosures include CVE-2016-15057 and CVE-2025-70982 (both CVSS 9.9), with the latter involving incorrect access control in SpringBlade's importUser function. Patch availability stands at 0%, requiring organizations to prioritize compensating controls and monitoring until fixes become available.
Immediate action: Organizations running Microsoft Windows, HPE OneView, Cisco Unified Communications Manager, Zimbra Collaboration Suite, or VMware vCenter Server should assess exposure to the 15 actively exploited vulnerabilities. With no patches currently available, implement network segmentation, enhanced monitoring, and access restrictions for affected systems.
Microsoft Office PowerPoint Code Injection Vulnerability - Active in CISA KEV catalog.
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability - Active in CISA KEV catalog.
Gogs Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Information Disclosure Vulnerability - Active in CISA KEV catalog.
Cisco Unified Communications Products Code Injection Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability - Active in CISA KEV catalog.
Versa Concerto Improper Authentication Vulnerability - Active in CISA KEV catalog.
Vite Vitejs Improper Access Control Vulnerability - Active in CISA KEV catalog.
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability - Active in CISA KEV catalog.
Linux Kernel Integer Overflow Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
GNU InetUtils Argument Injection Vulnerability - Active in CISA KEV catalog.
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary commands on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.
vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows attackers to escape the sandbox and run arbitrary code. In lib/setup-sandbox.js, the callback function of `localPromise.prototype.then` is sanitized, but `globalPromise.prototype.then` is not sanitized. The return value of async functions is `globalPromise` object. Version 3.10.2 fixes the issue.
Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
Deep Instinct Windows Agent 1
beat-access for Windows version 3
The AhaChat Messenger Marketing WordPress plugin through 1
Out-of-bounds Write vulnerability in Apache Hadoop HDFS native client
Python-Multipart is a streaming multipart parser for Python
BentoML is a Python library for building online serving systems optimized for AI apps and model inference
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server
Single Sign-On Portal System developed by WellChoose has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server
Skipper is an HTTP router and reverse proxy for service composition
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards
A Heap-based Buffer Overflow vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file
ASDA-Soft Stack-based Buffer Overflow Vulnerability
A flaw has been found in Tenda AC23 16
A flaw was found in KubeVirt Containerized Data Importer (CDI)
MobSF is a mobile application security testing tool used
HTC IPTInstaller 4
KMSpico 17
Magic Mouse 2 Utilities 2
Microvirt MEMU Play 3
An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file
IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges
MiniTool ShadowMaker 3
PDF Complete 3
Kite 1
IDT PC Audio 1
An issue in continuous
Multiple denial of service vulnerabilities exist in React Server Components, affecting the following packages: react-server-dom-parcel, react-server-dom-turbopack, react-server-dom-webpack
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image
A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3
A vulnerability was found in code-projects Online Examination System 1
A flaw has been found in code-projects Online Music Site 1
A flaw has been found in Hisense TransTech Smart Bus Management System up to 20260113
A vulnerability was detected in D-Link DIR-615 up to 4
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting