CVE-2025-8110
Gogs Path Traversal Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Yesterday's disclosures contained zero critical-severity CVEs, representing a complete reduction from the prior day's 10 critical vulnerabilities. High-priority CVE volume decreased significantly to 42 entries, down 46% from the previous day's 78 disclosures. The actively exploited vulnerability count remains elevated with 13 CISA KEV additions affecting Microsoft Windows (CVE-2026-20805), Cisco Unified Communications Manager (CVE-2026-20045), and VMware vCenter Server (CVE-2024-37079). Additional KEV entries impact Microsoft Office (CVE-2026-21509), Zimbra Collaboration Suite (CVE-2025-68645), GNU InetUtils (CVE-2026-24061), and the Linux kernel (CVE-2018-14634). Current patch availability stands at 0%, requiring organizations to prioritize compensating controls and monitoring for affected systems.
Immediate action: Organizations running Microsoft Windows, Office, Cisco UCM, VMware vCenter, Zimbra, or Linux systems should implement network segmentation and enhanced logging for affected components. With zero patches currently available, focus on threat detection and applying compensating controls until vendor remediations are released.
Gogs Path Traversal Vulnerability - Active in CISA KEV catalog.
Microsoft Windows Information Disclosure Vulnerability - Active in CISA KEV catalog.
Cisco Unified Communications Products Code Injection Vulnerability - Active in CISA KEV catalog.
Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability - Active in CISA KEV catalog.
Versa Concerto Improper Authentication Vulnerability - Active in CISA KEV catalog.
Vite Vitejs Improper Access Control Vulnerability - Active in CISA KEV catalog.
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability - Active in CISA KEV catalog.
Linux Kernel Integer Overflow Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability - Active in CISA KEV catalog.
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability - Active in CISA KEV catalog.
GNU InetUtils Argument Injection Vulnerability - Active in CISA KEV catalog.
Microsoft Office Security Feature Bypass Vulnerability - Active in CISA KEV catalog.
Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes
Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter
IBM Db2 for Windows 12
e-Learning PHP Script 0
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server)Â 11
The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'orderform_data' AJAX action in all versions up to, and including, 1
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry and Trade Ltd
SQL injection vulnerability in geopandas before v
A security flaw has been discovered in Totolink A3600R 5
ChurchCRM is an open-source church management system
Koken CMS 0
Wing FTP Server 6
Nidesoft DVD Ripper 5
Port Forwarding Wizard 4
Socusoft Photo to Video Converter Professional 8
FTPDummy 4
Simple Startup Manager 1
RM Downloader 2
Code Blocks 17
Frigate Professional 3
Frigate 3
Infor Storefront B2B 1
Outline Service 1
Andrea ST Filters Service 1
Popcorn Time 6
Atomic Alarm Clock 6
Salt's junos execution module contained an unsafe YAML decode/load usage
Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node
A flaw was found in Undertow
fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback
HelloWeb 2
Code Blocks 20
Frigate 2
OpenCTI 3
A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon
A security vulnerability has been detected in itsourcecode Directory Management System 1
A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon
A security vulnerability has been detected in itsourcecode Student Management System 1
HotCRP is conference review software
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation
Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary commands on the device by crafting specific messages
Navigate CMS 2