A flaw was found in Moodle
Description
A flaw was found in Moodle
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 21553 vulnerabilities with AI analyst insights
A flaw was found in Moodle
A flaw was found in Moodle
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw was found in moodle
A flaw was found in moodle
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw was found in Moodle
A flaw was found in Moodle
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw was found in Moodle
A flaw was found in Moodle
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A flaw was found in Moodle
A flaw was found in Moodle
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to ex...
A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15 allows remote attackers to execute arbitrary code via inline JSX expressions in an MDX file
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Nordic Semiconductor IronSide SE for nRF54H20 before 23
Nordic Semiconductor IronSide SE for nRF54H20 before 23
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4
Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0
The Code Engine plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 0
---METADATA---
VENDOR: tigroumeow
PRODUCT: Code Engine – PHP Snippets, AI Functions & Automation for WordPress
AFFECTED_VERSIONS: 0 through 0.3.5
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A command injection vulnerability in the Code Engine WordPress plugin allows authenticated users to execute arbitrary code on the underlying server.
Executive Summary:
An authenticated remote code execution vulnerability in the Code Engine WordPress plugin poses a severe risk, allowing attackers to execute commands on the host server.
Vulnerability Details
CVE-ID: CVE-2025-6784
Affected Software: tigroumeow Code Engine
Affected Versions: 0 through 0.3.5
Vulnerability: This is a Command Injection (CWE-77) vulnerability that occurs due to improper neutralization of special elements used in system commands. While the exploit requires authenticated access, it grants the attacker the ability to execute arbitrary commands, effectively giving them control over the web server.
Business Impact
With a CVSS score of 8.8, this high-severity vulnerability could lead to total server compromise, data exfiltration, and the installation of persistent backdoors. The business impact is significant, as it enables an attacker to move beyond the application layer into the underlying infrastructure.
Remediation Plan
Immediate Action: Update the Code Engine plugin to the latest version immediately as specified in the vendor's security advisory.
Proactive Monitoring: Monitor server logs for unexpected system calls or process execution originating from the web server user account.
Compensating Controls: Ensure the web server process runs with the principle of least privilege, limiting the scope of what an attacker can execute if the application is compromised.
Exploitation Status
Public Exploit Available: False
Analyst Notes: As of Jul 11, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Remote code execution is among the most severe security risks. Administrators must verify the status of their Code Engine plugin and apply the patch provided by the vendor to prevent unauthorized command execution and maintain the integrity of the WordPress environment.
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() function in all versions up to, and...
The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() function in all versions up to, and including, 1
Executive Summary: A high-severity SQL Injection vulnerability in the GoZen Forms plugin for WordPress allows unauthenticated attackers to execute arbitrary SQL queries, potentially leading to sensitive data exfiltration.
Vulnerability Details
CVE-ID: CVE-2025-6783
Affected Software: WordPress GoZen Forms plugin
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The GoZen Forms plugin is vulnerable to SQL Injection due to improper sanitization of user-supplied input in the 'forms-id' parameter of the emdedSc() function. An unauthenticated attacker can craft a malicious request to execute arbitrary SQL commands on the underlying WordPress database.
Business Impact
A successful exploit could allow an attacker to read, modify, or delete sensitive data from the WordPress database, including user information, content, and configuration settings. This poses a significant risk of a data breach, reputational damage, and potential website defacement. The assigned CVSS score of 7.5 reflects the high severity of this vulnerability.
Remediation Plan
Immediate Action: Immediately update the GoZen Forms plugin to the latest patched version provided by the vendor to eliminate the vulnerability. If the plugin is not essential, consider deactivating and deleting it as an alternative.
Proactive Monitoring: Monitor web server and database logs for unusual or excessively long SQL queries, especially those targeting the vulnerable function. Review for any signs of unauthorized access or data modification.
Compensating Controls: Implement a properly configured Web Application Firewall (WAF) with rules designed to detect and block common SQL Injection attack patterns, which can serve as a virtual patch.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 6, 2025, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation by unauthenticated attackers is high.
Analyst Recommendation
Given the high-severity rating and the potential for unauthenticated exploitation, this vulnerability presents a critical risk to affected WordPress sites. We strongly recommend that administrators prioritize applying the vendor-supplied update immediately to prevent potential data compromise and unauthorized database access.
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
An issue was discovered in K7 Ultimate Security 17
An issue was discovered in K7 Ultimate Security 17
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10
A vulnerability in the Multimedia Email component of Mitel MiContact Center Business through 10
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm() function in all versions up...
The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm() function in all versions up to, and including, 1
Executive Summary:
A high-severity SQL Injection vulnerability in the GoZen Forms plugin for WordPress allows unauthenticated attackers to extract sensitive information from the database.
Vulnerability Details
CVE-ID: CVE-2025-6782
Affected Software: WordPress GoZen Forms plugin
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The GoZen Forms plugin for WordPress is vulnerable to an unauthenticated SQL Injection. The flaw exists in the dirGZActiveForm() function due to insufficient sanitization of user-supplied input to the forms-id parameter, allowing an attacker to execute arbitrary SQL commands.
Business Impact
A successful exploit could allow an attacker to read, modify, or delete sensitive data from the WordPress database, including user credentials, personal information, and site content. This vulnerability is rated High with a CVSS score of 7.5, reflecting the potential for significant data compromise and loss of confidentiality and integrity.
Remediation Plan
Immediate Action: Administrators should immediately update the GoZen Forms plugin to the latest patched version as specified by the vendor. If a patch is not yet available or the plugin is not essential, consider disabling or uninstalling it.
Proactive Monitoring: Monitor web server and database logs for unusual or malformed SQL queries, paying close attention to requests involving the dirGZActiveForm() function.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules designed to detect and block common SQL Injection attack patterns as a virtual patch.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of July 6, 2025, there is no public information indicating active exploitation of this vulnerability. However, SQL Injection flaws are trivial to exploit once discovered, making the potential for future exploitation high.
Analyst Recommendation
Given the high severity of this vulnerability and the ease of exploitation for SQL Injection flaws, immediate action is required. We strongly recommend that all administrators prioritize the deployment of the vendor-supplied patch to prevent potential data breaches and unauthorized access to the application database.
Update WordPress plugin/theme to the latest version. Review WordPress security settings and remove if no longer needed.
An issue was discovered in Weaviate OSS before 1
An issue was discovered in Weaviate OSS before 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
IKUS Rdiffweb before 2
IKUS Rdiffweb before 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a...
An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.
---METADATA---
VENDOR: DriveLock
PRODUCT: Operations Center
AFFECTED_VERSIONS: 25.1.2 through 25.1.4
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A Cross-Site Scripting (XSS) vulnerability in DriveLock Operations Center allows unauthenticated remote attackers to achieve session takeover.
Executive Summary:
A critical Cross-Site Scripting vulnerability in DriveLock Operations Center allows unauthenticated attackers to perform session hijacking and gain unauthorized access.
Vulnerability Details
CVE-ID: CVE-2025-67787
Affected Software: DriveLock Operations Center
Affected Versions: 25.1.2 through 25.1.4
Vulnerability: This is a Cross-Site Scripting (XSS) vulnerability that allows for remote code execution or session manipulation. The vulnerability is exploitable by an unauthenticated attacker, as indicated by the CVSS vector PR:N.
Business Impact
Successful exploitation of this vulnerability allows an attacker to hijack user sessions, potentially granting them full administrative control over the DriveLock management console. Given the CVSS score of 9.6, this represents a critical risk of data breach, unauthorized system configuration changes, and severe compromise of internal security policies.
Remediation Plan
Immediate Action: Update DriveLock Operations Center to version 25.1.5 or later as specified in the vendor security bulletin.
Proactive Monitoring: Review web server and application logs for suspicious URL parameters containing script tags or encoded payloads.
Compensating Controls: Deploy a Web Application Firewall (WAF) with strict XSS filtering rules to inspect incoming traffic and block malicious script injection attempts.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Dec 17, 2025, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The high CVSS score is driven by the potential for full session compromise via a remote, unauthenticated vector.
Analyst Recommendation
This vulnerability presents a significant risk to organizational infrastructure due to the potential for administrative account takeover. Administrators must prioritize updating the DriveLock Operations Center to the patched version 25.1.5 immediately to prevent potential exploitation.
Update An issue was discovered in Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privilege...
An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged users can manipulate privileged processes to gain more privileges on Windows computers.
Executive Summary:
A critical privilege escalation vulnerability has been discovered in multiple versions of DriveLock security products. This flaw allows a local, unprivileged user on a Windows computer to manipulate privileged DriveLock processes, enabling them to gain full administrative control over the system. Successful exploitation could lead to a complete system compromise, data theft, or the deployment of malware such as ransomware.
Vulnerability Details
CVE-ID: CVE-2025-67781
Affected Software: DriveLock Multiple Products
Affected Versions: DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5
Vulnerability: This vulnerability is a local privilege escalation (LPE) on the Windows operating system. An attacker with standard, low-privilege user access to an endpoint can exploit an unspecified flaw within a DriveLock process that is running with elevated (e.g., SYSTEM) permissions. By manipulating this process, the attacker can force it to execute arbitrary code with the same high-level privileges, effectively escalating their own permissions from a standard user to a system administrator.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.9, reflecting the ease of exploitation and the total impact on a compromised system. An attacker who successfully exploits this flaw gains complete control over the affected endpoint. This allows them to bypass all security controls, install persistent malware, access, modify, or exfiltrate any sensitive data on the machine, and potentially use the compromised system as a pivot point to attack other resources on the corporate network. The direct risks to the organization include data breaches, ransomware infection, operational disruption, and reputational damage.
Remediation Plan
Immediate Action: Immediately apply the security updates provided by the vendor. Administrators should update all affected DriveLock installations to the following patched versions or later:
After patching, monitor systems for any signs of exploitation attempts and review security and application logs for anomalous activity preceding the update.
Proactive Monitoring: Security teams should monitor for indicators of compromise related to this vulnerability. This includes observing Windows Security Event Logs for unusual process creation originating from DriveLock services (e.g., cmd.exe or powershell.exe spawned by a DriveLock process). Monitor for unexpected file modifications within DriveLock's installation directories and for suspicious command-line arguments passed to system utilities.
Compensating Controls: If immediate patching is not feasible, implement compensating controls to reduce risk. Enforce the principle of least privilege by ensuring standard user accounts have no unnecessary permissions. Utilize application control or whitelisting solutions to prevent the execution of unauthorized tools that an attacker might use post-escalation. Deploy and configure an Endpoint Detection and Response (EDR) solution to detect and block suspicious behavior patterns associated with privilege escalation.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Dec 17, 2025, there are no known public proof-of-concept exploits or reports of this vulnerability being actively exploited in the wild. However, due to the critical CVSS score and the low complexity of the attack, it is highly probable that threat actors will reverse-engineer the vendor's patch to develop a functional exploit.
Analyst Recommendation
Given the critical severity (CVSS 9.9) of this vulnerability, immediate remediation is strongly recommended. This flaw provides a direct path for a low-privilege user to achieve full system compromise, representing a significant threat to endpoint security. Although it is not currently listed on the CISA KEV catalog, its high impact and low attack complexity warrant urgent attention. Organizations must prioritize the deployment of the vendor-provided patches across all affected Windows endpoints to mitigate the risk of compromise.
Update An issue was discovered in DriveLock Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a spe...
It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a denial of service attack in a specific case
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenEMR is a free and open source electronic health records and medical practice management application
OpenEMR is a free and open source electronic health records and medical practice management application
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
ChurchCRM is an open-source church management system
ChurchCRM is an open-source church management system
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows
Lightning Flow Scanner provides a A CLI plugin, VS Code Extension and GitHub Action for analysis and optimization of Salesforce Flows
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
MyHoard is a daemon for creating, managing and restoring MySQL backups
MyHoard is a daemon for creating, managing and restoring MySQL backups
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerabi...
DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid diagram rendering component that allows arbitrary JavaScript execution. Due to the exposure of the Electron IPC renderer to the DOM, this Cross-Site Scripting (XSS) flaw escalates to full Remote Code Execution (RCE), allowing an attacker to execute arbitrary system commands. Two concurrent issues, unsafe Mermaid configuration and an exposed IPC interface, cause this issue. Version 0.5.3 contains a patch.
Executive Summary:
A critical vulnerability has been identified in the DeepChat AI agent platform, which could allow an attacker to take complete control of an affected system. The flaw originates in the diagram rendering component and can be triggered by a specially crafted diagram, leading to arbitrary code execution. Successful exploitation would allow an attacker to steal data, install malware, or use the compromised machine to attack other systems on the network.
Vulnerability Details
CVE-ID: CVE-2025-67744
Affected Software: DeepChat is an Multiple Products
Affected Versions: All versions prior to 0.5.3
Vulnerability: This vulnerability is a result of two combined issues. First, the Mermaid diagram rendering component is improperly configured, allowing for the execution of arbitrary JavaScript when a malicious diagram is processed (Cross-Site Scripting). Second, the application, built on the Electron framework, insecurely exposes its Inter-Process Communication (IPC) renderer interface to the web content. An attacker can exploit this by crafting a malicious diagram that, when rendered by a victim, executes JavaScript code to access the exposed IPC interface and send commands to the main application process, which has system-level privileges. This escalates the initial XSS vulnerability to full Remote Code Execution (RCE), allowing the attacker to run any command on the underlying operating system.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.6, indicating a high potential for significant damage. A successful exploit results in a complete compromise of the system running the DeepChat application. Potential consequences include the exfiltration of sensitive data such as proprietary AI models, user credentials, and confidential documents; the deployment of ransomware or spyware; and using the compromised system as a staging point for further attacks against the internal network. This poses a severe risk to data confidentiality, integrity, and availability, and could lead to major financial and reputational damage.
Remediation Plan
Immediate Action: Immediately update all instances of DeepChat to version 0.5.3 or later, as this version contains the patch for the vulnerability. After updating, thoroughly review application and system logs for any signs of suspicious activity, such as unexpected commands or network connections, which may indicate a prior compromise.
Proactive Monitoring: Implement enhanced monitoring on systems running DeepChat. Look for suspicious child processes being spawned by the DeepChat application (e.g., cmd.exe, powershell.exe, /bin/sh), unusual outbound network connections to unknown IP addresses, and any logs related to errors in the Mermaid rendering engine.
Compensating Controls: If immediate patching is not feasible, implement the following controls to mitigate risk:
Exploitation Status
Public Exploit Available: False
Analyst Notes: As of Dec 16, 2025, there are no known public proof-of-concept exploits or active exploitation campaigns targeting this vulnerability. However, due to the critical severity and the well-understood nature of XSS-to-RCE in Electron applications, it is highly likely that a functional exploit will be developed and released by threat actors in the near future.
Analyst Recommendation
Given the critical CVSS score of 9.6 and the direct path to Remote Code Execution, this vulnerability represents a significant and immediate threat to the organization. Although it is not currently listed on the CISA KEV catalog, its severity makes it a prime candidate for future inclusion. We strongly recommend that all system administrators prioritize the immediate deployment of the patch (version 0.5.3) to all affected DeepChat instances to prevent a full system compromise.
Update DeepChat is an Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
squid/cachemgr
squid/cachemgr
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Valkey is a distributed key-value database
Valkey is a distributed key-value database
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
LMDeploy is a toolkit for compressing, deploying, and serving LLMs
LMDeploy is a toolkit for compressing, deploying, and serving LLMs
Executive Summary:
A high-severity vulnerability has been discovered in multiple LMDeploy products, a toolkit used for deploying and serving Large Language Models (LLMs). An unauthenticated attacker could remotely exploit this flaw to execute arbitrary code on the affected server, potentially leading to a complete system compromise, theft of sensitive data, and disruption of AI-powered services. Organizations are urged to apply security updates immediately to mitigate this critical risk.
Vulnerability Details
CVE-ID: CVE-2025-67729
Affected Software: LMDeploy Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability exists in the way LMDeploy processes incoming inference requests. A remote, unauthenticated attacker can send a specially crafted request to an exposed API endpoint. Due to improper input validation, this malicious request can trigger a deserialization flaw, allowing the attacker to execute arbitrary code with the privileges of the LMDeploy service account on the underlying server.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.8. Successful exploitation could have severe consequences for the organization, including the complete compromise of the server hosting the LLM. Potential impacts include the theft of proprietary models, exfiltration of sensitive data processed by the LLM, denial of service impacting critical applications, and the attacker gaining a persistent foothold within the corporate network to launch further attacks. Such a breach could lead to significant financial loss, reputational damage, and regulatory penalties.
Remediation Plan
Immediate Action: Apply vendor security updates immediately across all affected LMDeploy instances. After patching, review server and application access logs for any signs of compromise that may have occurred prior to the update.
Proactive Monitoring: Implement enhanced monitoring of systems running LMDeploy. Specifically, security teams should look for:
Compensating Controls: If immediate patching is not feasible, implement the following controls to reduce the risk of exploitation:
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 27, 2025, there is no known public proof-of-concept exploit code, and there are no confirmed reports of this vulnerability being actively exploited in the wild. However, given the high severity and the potential for remote code execution, it is highly likely that threat actors will reverse-engineer the patch and develop exploit code in the near future.
Analyst Recommendation
Given the high CVSS score of 8.8, this vulnerability represents a critical risk to the organization. We strongly recommend that all teams utilizing LMDeploy prioritize the immediate application of the vendor-supplied security patches. While this CVE is not currently listed on the CISA KEV catalog, its severity makes it a prime candidate for future inclusion. Organizations that cannot patch immediately must implement the recommended compensating controls and actively monitor for any signs of attempted exploitation.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public...
Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0.
Executive Summary:
A critical vulnerability has been identified in Fireshare software, which allows an attacker to execute arbitrary commands on the server. This flaw can be exploited by uploading a video file with a specially crafted filename, potentially leading to a complete system compromise, data theft, and significant service disruption. The vulnerability is especially dangerous on instances where public uploads are enabled, as it allows unauthenticated attackers to gain control of the server.
Vulnerability Details
CVE-ID: CVE-2025-67728
Affected Software: Fireshare facilitates Multiple Products
Affected Versions: Versions 1.2.30 and below
Vulnerability: The application is vulnerable to command injection. It fails to properly sanitize user-supplied input for filenames during the video upload process. An attacker can craft a filename containing shell metacharacters (e.g., ;, |, &&) and system commands. When the application processes the uploaded file, it concatenates this malicious filename directly into a system shell command, causing the injected commands to be executed with the privileges of the web server user. This can also be used for path traversal by including sequences like ../ in the filename, allowing the attacker to write files to arbitrary locations on the server, which could be used to upload a web shell for persistent access.
Business Impact
This vulnerability is rated as critical with a CVSS score of 9.8, reflecting the high potential for severe damage. Successful exploitation could lead to a full compromise of the host server, granting an attacker the ability to access, modify, or exfiltrate all stored data, including user media and sensitive application information. An attacker could also leverage this access to install malware (such as ransomware or crypto miners), disrupt service availability, or use the compromised server as a pivot point to attack other systems within the internal network. The potential for reputational damage and financial loss resulting from a data breach or service outage is significant.
Remediation Plan
Immediate Action: Immediately upgrade all instances of Fireshare to version 1.3.0 or later, which contains the fix for this vulnerability. After patching, review web server and application logs for any signs of past exploitation attempts, such as upload requests with unusual filenames containing special characters or command syntax.
Proactive Monitoring:
;, |, &, $(), `) or path traversal sequences (../).sh, bash, curl, wget)./tmp, or system binary paths.Compensating Controls:
If immediate patching is not feasible:
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 12, 2025, there are no known public exploits for this vulnerability. However, given the critical severity (CVSS 9.8) and the relative simplicity of exploiting command injection flaws, it is highly probable that proof-of-concept code will be developed and released by security researchers. Threat actors are expected to begin actively scanning for and exploiting vulnerable systems shortly after this public disclosure.
Analyst Recommendation
Due to the critical severity of this vulnerability, we strongly recommend that organizations treat this as an emergency. The primary and most effective remediation is to apply the security update provided by the vendor immediately. Although this CVE is not currently listed on the CISA KEV catalog, its high impact and ease of exploitation make it a prime candidate for future inclusion. Organizations should prioritize patching all affected systems and subsequently hunt for any indicators of compromise to ensure their environment has not already been breached.
Update Fireshare facilitates Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Tornado is a Python web framework and asynchronous networking library
Tornado is a Python web framework and asynchronous networking library
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Tornado is a Python web framework and asynchronous networking library
Tornado is a Python web framework and asynchronous networking library
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts
An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts
---METADATA---
VENDOR: PHP Jabbers
PRODUCT: Appointment Scheduler (and others)
AFFECTED_VERSIONS: Various PHP Jabbers products: Appointment Scheduler (<4.1), Bus Reservation System (<2.1), Car Park Booking System (<4.1), Car Rental Script (<4.1), Cinema Booking System (<2.1), Event Booking Calendar (<5.1)
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
Multiple PHP Jabbers scripts contain an authenticated SQL injection vulnerability, allowing privileged users to execute unauthorized database commands.
Executive Summary:
An authenticated SQL injection vulnerability in several PHP Jabbers scripts enables high-privileged attackers to compromise backend databases.
Vulnerability Details
CVE-ID: CVE-2025-67650
Affected Software: PHP Jabbers
Affected Versions: Appointment Scheduler <4.1, Bus Reservation System <2.1, Car Park Booking System <4.1, Car Rental Script <4.1, Cinema Booking System <2.1, Event Booking Calendar <5.1
Vulnerability: This is an SQL injection vulnerability (CWE-89) that requires the attacker to have administrative privileges. By injecting malicious SQL statements, an attacker can manipulate database queries.
Business Impact
While this vulnerability requires authentication, the potential for unauthorized data access or modification within the booking systems remains high. A CVSS score of 8.6 indicates a severe impact on the confidentiality and integrity of the data stored within these applications, which could disrupt business operations and lead to the exposure of sensitive client information.
Remediation Plan
Immediate Action: Update all affected PHP Jabbers software modules to the versions specified as fixed in the vendor security advisory.
Proactive Monitoring: Review application audit logs to identify any unusual administrative activities or unexpected database errors.
Compensating Controls: Restrict administrative access to these systems to a limited set of trusted internal IP addresses and implement strict input validation at the application layer.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of August 1, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is limited by the requirement for administrative authentication, which acts as a barrier to exploitation but does not eliminate the risk from malicious or compromised insider accounts.
Analyst Recommendation
Organizations using these PHP Jabbers scripts should verify their current versions against the list provided. It is imperative to perform the necessary updates to the specified fixed versions to ensure that administrative privileges cannot be abused to compromise the underlying database infrastructure.
Apply vendor patches immediately. Review database access controls and enable query logging.
A SQL injection vulnerability in the PHP Jabbers Car Rental Script allows unauthenticated attackers to execute malicious database queries through impr...
A SQL injection vulnerability in the PHP Jabbers Car Rental Script allows unauthenticated attackers to execute malicious database queries through improperly sanitized sorting parameters.
---METADATA---
VENDOR: PHP Jabbers
PRODUCT: Car Rental Script
AFFECTED_VERSIONS: 0 up to (excluding) 4.1
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A SQL injection vulnerability in the PHP Jabbers Car Rental Script allows unauthenticated attackers to execute malicious database queries through improperly sanitized sorting parameters.
Executive Summary:
An unauthenticated SQL injection vulnerability in PHP Jabbers Car Rental Script could allow attackers to gain unauthorized access to sensitive database information.
Vulnerability Details
CVE-ID: CVE-2025-67649
Affected Software: PHP Jabbers Car Rental Script
Affected Versions: 0 up to (excluding) 4.1
Vulnerability: This is a classic SQL injection flaw (CWE-89) where user-supplied input in sorting functions is not properly neutralized. The vulnerability is exploitable by unauthenticated attackers, allowing them to interfere with the backend database.
Business Impact
The ability to perform SQL injection can lead to unauthorized data exfiltration, modification of database contents, or administrative bypass. Given the CVSS score of 9.3, this vulnerability represents a critical threat to the confidentiality and integrity of the application.
Remediation Plan
Immediate Action: Update the PHP Jabbers Car Rental Script to version 4.1 or later to apply the necessary input sanitization.
Proactive Monitoring: Monitor database query logs for suspicious syntax or unexpected query patterns indicative of SQL injection attempts.
Compensating Controls: Utilize a Web Application Firewall (WAF) configured to detect and block common SQL injection patterns in HTTP requests.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of Jul 31, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly automatable, which increases the risk of discovery by automated scanners.
Analyst Recommendation
This vulnerability carries a critical risk rating and should be addressed as a priority. Administrators must update the software immediately to prevent potential data breaches stemming from malicious database interaction.
Update PHP Jabbers Car Rental Script to the latest version. Monitor for exploitation attempts and review access logs.
Shopware is an open commerce platform
Shopware is an open commerce platform
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
OpenEMR is a free and open source electronic health records and medical practice management application
OpenEMR is a free and open source electronic health records and medical practice management application
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite)
LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite)
Executive Summary:
A high-severity vulnerability has been identified in multiple LangGraph products, specifically within the SQLite Checkpoint component. This flaw could allow a remote attacker to manipulate the underlying database, potentially leading to unauthorized access to sensitive data, data corruption, or denial of service. Immediate patching is required to mitigate the significant risk to data confidentiality and integrity.
Vulnerability Details
CVE-ID: CVE-2025-67644
Affected Software: LangGraph Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability is an SQL injection flaw within the LangGraph SQLite CheckpointSaver component. The component fails to properly sanitize input when saving application state checkpoints to the SQLite database. An unauthenticated remote attacker can craft malicious input that, when processed by the CheckpointSaver, is included in a raw SQL query. This allows the attacker to execute arbitrary SQL commands within the context of the application's database user, enabling them to read, modify, or delete data, or potentially achieve remote code execution depending on the database configuration.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 7.3. Successful exploitation could have a significant business impact, including the compromise of sensitive application data, conversation histories, or user information stored in the state management database. An attacker could manipulate application checkpoints to alter program flow or poison data, leading to a loss of data integrity and trust in the system. Furthermore, a successful attack could result in application downtime or a complete denial of service, disrupting business operations.
Remediation Plan
Immediate Action: Apply the security updates provided by LangGraph immediately across all affected systems. After patching, it is critical to monitor for any signs of attempted exploitation by reviewing application and database logs for suspicious activity that may have occurred prior to remediation.
Proactive Monitoring: Security teams should monitor database logs for malformed or unusual SQL queries, particularly those targeting the checkpoint tables. Monitor application logs for unexpected errors or crashes related to the checkpointing mechanism. Network monitoring should be in place to detect anomalous outbound connections from the application server, which could indicate data exfiltration.
Compensating Controls: If immediate patching is not feasible, consider implementing a Web Application Firewall (WAF) with specific rules designed to detect and block common SQL injection patterns in traffic destined for the affected application. Additionally, ensure the database user account has the minimum necessary permissions (principle of least privilege) to limit the impact of a potential compromise.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 11, 2025, there are no known public exploits or active exploitation campaigns targeting this vulnerability. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. However, SQL injection vulnerabilities are well understood and exploits can be developed rapidly by threat actors.
Analyst Recommendation
Given the High severity (CVSS 7.3) of this SQL injection vulnerability, organizations must treat its remediation as a high priority. The potential for data compromise and service disruption presents a significant risk. We strongly recommend that all organizations using affected LangGraph products apply the vendor-provided security patches immediately without delay. Although there is no current evidence of active exploitation, the ease of developing an exploit for this type of flaw means that the window of opportunity for attackers is likely to be short.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Jenkins Coverage Plugin 2
Jenkins Coverage Plugin 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Jenkins 2
Jenkins 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forgery
Cross-Site Request Forgery (CSRF) vulnerability in tmtraderunner Trade Runner traderunner allows Cross Site Request Forgery
Executive Summary:
A high-severity Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple tmtraderunner Trade products. This flaw could allow a remote attacker to trick an authenticated user into performing unintended actions within the application, such as modifying data or executing transactions, potentially leading to account compromise and unauthorized activity.
Vulnerability Details
CVE-ID: CVE-2025-67625
Affected Software: tmtraderunner Trade Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The application is susceptible to a Cross-Site Request Forgery (CSRF) attack. This vulnerability exists because the application fails to properly validate that a state-changing request (e.g., a POST request to modify settings or execute a trade) was intentionally initiated by the authenticated user. An attacker can exploit this by crafting a malicious webpage, email, or link that contains a forged request and tricking a logged-in user into visiting it. The user's browser will automatically include their session cookies with the request, causing the vulnerable application to process it as a legitimate action performed by the user.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.8. Successful exploitation could have a significant business impact, including unauthorized modification of critical data, fraudulent transactions, and potential account takeover. For an organization utilizing the "Trade Runner" software, this could lead to direct financial loss, reputational damage, and loss of customer trust. The vulnerability bypasses standard authentication controls, as it leverages an already authenticated user's session to perform malicious actions on their behalf.
Remediation Plan
Immediate Action: The primary remediation is to apply the security updates provided by tmtraderunner Trade immediately across all affected systems. After patching, system administrators should review application and web server access logs for any unusual or unauthorized state-changing requests that may indicate prior exploitation attempts.
Proactive Monitoring: Implement enhanced monitoring of application logs, specifically looking for a high volume of unexpected actions (e.g., configuration changes, data submissions) from a single user session. Monitor web server logs for requests to sensitive functions that lack an expected "Referer" header or have a "Referer" from an untrusted or external domain, as this can be an indicator of a CSRF attempt.
Compensating Controls: If immediate patching is not feasible, consider implementing a Web Application Firewall (WAF) with rules designed to detect and block common CSRF attack patterns. As a user-level precaution, advise employees to log out of the application when it is not in active use and to exercise caution when clicking links in emails or on untrusted websites.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 26, 2025, there are no known public exploits or active exploitation campaigns targeting this vulnerability. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. However, given the nature of CSRF flaws, proof-of-concept exploits can be developed with relative ease.
Analyst Recommendation
Given the high CVSS score of 8.8, it is strongly recommended that the organization prioritizes the immediate deployment of the vendor-supplied patches to all affected "Trade Runner" products. Although there is no evidence of active exploitation, the potential for significant financial and operational impact is substantial. A risk assessment should be conducted to identify all instances of the vulnerable software, and a patching schedule should be implemented without delay.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6...
Server-Side Request Forgery (SSRF) vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Server Side Request Forgery.This issue affects 6Storage Rentals: from n/a through <= 2.19.9.
---METADATA---
VENDOR: 6Storage
PRODUCT: 6Storage Rentals
AFFECTED_VERSIONS: n/a through 2.19.9
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
A Server-Side Request Forgery (SSRF) vulnerability in 6Storage Rentals allows unauthenticated attackers to force the server to make unauthorized requests to internal resources.
Executive Summary:
A critical Server-Side Request Forgery vulnerability in 6Storage Rentals enables attackers to bypass network perimeters, posing a significant risk to internal infrastructure.
Vulnerability Details
CVE-ID: CVE-2025-67623
Affected Software: 6Storage 6Storage Rentals
Affected Versions: n/a through 2.19.9
Vulnerability: This SSRF vulnerability allows an unauthenticated attacker to manipulate the application into performing unintended network requests. By submitting crafted requests, the attacker can interact with internal services that are not typically accessible from the external network.
Business Impact
The ability to perform SSRF attacks allows malicious actors to scan internal networks, access sensitive metadata services, or interact with backend databases. With a CVSS score of 9.1, this vulnerability poses a critical risk of data exfiltration and potential compromise of the entire backend infrastructure, leading to significant operational disruption.
Remediation Plan
Immediate Action: Upgrade 6Storage Rentals to a version beyond 2.19.9 as soon as a security update is released by the vendor.
Proactive Monitoring: Inspect server egress traffic logs for unusual outbound connections to internal IP ranges or sensitive cloud metadata endpoints (e.g., 169.254.169.254).
Compensating Controls: Implement strict egress filtering on the application server and utilize a Web Application Firewall (WAF) to block requests containing suspicious URL parameters or internal hostnames.
Exploitation Status
Public Exploit Available: Unknown
Analyst Notes: As of Dec 24, 2025, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Given the critical severity and the nature of SSRF vulnerabilities, immediate action is required to harden the network environment. Administrators should verify their current version and apply all available vendor patches, while concurrently restricting outbound network access for the application server to prevent exploitation.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS
Cross-Site Request Forgery (CSRF) vulnerability in titopandub Evergreen Post Tweeter evergreen-post-tweeter allows Stored XSS
Executive Summary:
A high-severity vulnerability has been identified in multiple titopandub Evergreen products, specifically within the Evergreen Post Tweeter component. This flaw allows an attacker to trick a logged-in user into unknowingly executing commands that inject persistent, malicious code into the application. Successful exploitation could lead to the compromise of user accounts, theft of sensitive data, and unauthorized control over the affected system.
Vulnerability Details
CVE-ID: CVE-2025-67622
Affected Software: titopandub Evergreen Multiple Products (specifically the evergreen-post-tweeter component)
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability is a chain of a Cross-Site Request Forgery (CSRF) weakness leading to a Stored Cross-Site Scripting (XSS) attack. The application lacks anti-CSRF tokens on sensitive functions within the 'evergreen-post-tweeter' component. An attacker can craft a malicious webpage or link and entice an authenticated administrator to click it. When the victim's browser visits the attacker's page, it will automatically and unknowingly submit a forged request to the vulnerable application, which the application trusts because the user is already authenticated. This forged request contains a malicious script payload which the application fails to properly sanitize before storing it in the database. This stored script will then execute in the browser of any user who views the compromised page, leading to potential session hijacking, data theft, or further attacks.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.8. Successful exploitation poses a significant risk to the organization. It could lead to the compromise of high-privilege administrator accounts, allowing an attacker to gain control over the application, access and exfiltrate sensitive data, or deface web content. The persistent nature of the Stored XSS means the malicious code remains active until found and removed, potentially affecting every user who views the infected content. This can result in significant reputational damage, loss of customer trust, and potential regulatory non-compliance depending on the data compromised.
Remediation Plan
Immediate Action: Apply the security updates provided by titopandub Evergreen immediately to all affected systems, prioritizing internet-facing and critical instances. After patching, it is crucial to monitor for any signs of prior exploitation by reviewing application and web server access logs for suspicious POST requests or unusual content modifications.
Proactive Monitoring: Implement enhanced logging and monitoring to detect potential exploitation attempts. Security teams should look for unexpected POST requests to the 'evergreen-post-tweeter' endpoints, especially from unknown or suspicious referrers. Monitor for saved content containing HTML <script> tags, onerror attributes, or other XSS vectors. Network traffic should be monitored for unusual outbound connections from clients accessing the application.
Compensating Controls: If immediate patching is not feasible, the following compensating controls can help reduce risk:
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 26, 2025, there are no known public exploits or active exploitation campaigns targeting this vulnerability. However, due to the high CVSS score and the common nature of CSRF and XSS vulnerabilities, it is highly likely that proof-of-concept exploits will be developed by security researchers and threat actors in the near future.
Analyst Recommendation
Given the high severity (CVSS 8.8) of this vulnerability, immediate action is required. The primary recommendation is to apply the vendor-supplied patches across all affected systems without delay. Although this vulnerability is not currently listed on the CISA KEV (Known Exploited Vulnerabilities) catalog, its severity makes it a prime candidate for future inclusion. Organizations should treat this as an urgent threat and, in addition to patching, implement the recommended monitoring controls to detect any potential post-patch exploitation attempts or signs of a prior compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Workflow eight-day-week-print-wo...
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in 10up Eight Day Week Print Workflow eight-day-week-print-workflow allows Retrieve Embedded Sensitive Data
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher C...
A vulnerability has been identified within Rancher Manager, where using self-signed CA certificates and passing the -skip-verify flag to the Rancher CLI login command without also passing the –cacert flag results in the CLI attempting to fetch CA certificates stored in Rancher’s setting cacerts
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' functio...
The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_register' function in all versions up to, and including, 3.6. This ...
Executive Summary:
A critical privilege escalation vulnerability has been identified in The Real Spaces WordPress theme, affecting multiple products. This flaw allows an unauthenticated attacker to create a new user account with full administrative privileges, potentially leading to a complete compromise of the affected website. Successful exploitation could result in data theft, website defacement, or the distribution of malware to visitors.
Vulnerability Details
CVE-ID: CVE-2025-6758
Affected Software: The Real Spaces - WordPress Properties Directory Theme
Affected Versions: All versions up to, and including, 3.6
Vulnerability: The vulnerability exists within the imic_agent_register function, which handles new user registrations. The function fails to properly sanitize or validate the user role data submitted during the registration process. An unauthenticated attacker can craft a malicious request to the registration endpoint, supplying parameters that assign the 'administrator' role to the newly created account, thereby escalating their privileges from a non-existent user to a full administrator.
Business Impact
This is a critical severity vulnerability with a CVSS score of 9.8. A successful exploit grants an attacker complete control over the WordPress website, posing a significant risk to the business. Potential consequences include the theft of sensitive customer or business data, unauthorized modification of website content, reputational damage, and financial loss. The compromised website could also be used to host phishing campaigns, distribute malware, or act as a pivot point for further attacks into the corporate network.
Remediation Plan
Immediate Action: Immediately update The Real Spaces Multiple Products to the latest version provided by the vendor to patch the vulnerability. After updating, review all existing user accounts, particularly those with administrative privileges, to identify and remove any unauthorized accounts that may have been created.
Proactive Monitoring: Monitor web server access logs for an unusual volume of requests to user registration pages or direct calls to the imic_agent_register function. Implement alerts for the creation of new administrative accounts. Regularly review site integrity by monitoring for unexpected file changes, new plugin installations, or modifications to core WordPress files.
Compensating Controls: If immediate patching is not feasible, consider implementing the following controls:
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Aug 19, 2025, there are no known public proof-of-concept exploits or active exploitation campaigns targeting this vulnerability. However, vulnerabilities of this type in popular WordPress themes are frequently and rapidly weaponized by threat actors. Organizations should assume that an exploit will become available shortly.
Analyst Recommendation
Given the critical CVSS score of 9.8 and the low complexity of exploitation, immediate action is required. Organizations using the affected WordPress theme must prioritize applying the vendor-supplied patch without delay to prevent a full website compromise. Although this vulnerability is not currently listed on the CISA KEV catalog, its high severity and potential impact make it a prime candidate for future inclusion and widespread exploitation.
Update The Real Spaces Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_...
The SEO Metrics plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization checks in both the seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function in versions 1
Executive Summary:
A high-severity vulnerability has been discovered in the SEO Metrics plugin for WordPress, identified as CVE-2025-6754. This flaw allows any authenticated user, regardless of their permission level, to gain administrative privileges on the affected website. Successful exploitation could lead to a complete site takeover, allowing an attacker to steal data, deface the website, or distribute malware to visitors.
Vulnerability Details
CVE-ID: CVE-2025-6754
Affected Software: WordPress SEO Metrics plugin
Affected Versions: All versions of the SEO Metrics plugin up to and including version 1.x.x. See vendor advisory for specific patched versions.
Vulnerability: The vulnerability is a Privilege Escalation due to missing capability or authorization checks on two separate functions within the plugin. The seo_metrics_handle_connect_button_click() AJAX handler and the seo_metrics_handle_custom_endpoint() function both fail to verify that the user making the request has sufficient permissions to perform administrative actions. An attacker with a low-privileged account, such as a 'subscriber', can send a specially crafted request to these functions to execute privileged operations, including elevating their own account to an administrator role.
Business Impact
This is a High severity vulnerability with a CVSS score of 8.8. Exploitation could lead to a complete compromise of the organization's WordPress website, resulting in significant business impact. Potential consequences include theft of sensitive customer or user data, financial loss, reputational damage from website defacement, and the use of the compromised website to host phishing campaigns or distribute malware. A site compromise could also lead to SEO penalties from search engines and a loss of customer trust.
Remediation Plan
Immediate Action: The primary remediation is to update the SEO Metrics plugin to the latest secure version provided by the vendor, which contains patches for this vulnerability. If the plugin is not critical to business operations, an alternative and highly effective measure is to deactivate and completely remove the plugin from the WordPress installation to eliminate the attack surface. After applying the patch, review all administrator-level accounts for any signs of unauthorized creation or modification.
Proactive Monitoring: Security teams should monitor web server and application logs for suspicious activity. Specifically, look for an unusual volume of POST requests to /wp-admin/admin-ajax.php with the actions seo_metrics_handle_connect_button_click or seo_metrics_handle_custom_endpoint, especially if originating from low-privileged users. Monitor for unexpected user privilege escalations or the creation of new administrative accounts in WordPress audit logs.
Compensating Controls: If immediate patching is not feasible, a Web Application Firewall (WAF) can be configured with rules to block or alert on requests targeting the vulnerable AJAX actions. Additionally, enforcing the principle of least privilege by disabling public user registration and regularly auditing existing user accounts can help reduce the risk of initial access by an attacker.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of August 3, 2025, there are no known public exploits specifically for CVE-2025-6754. However, vulnerabilities related to missing authorization in WordPress plugins are trivial to exploit once the details are public. It is highly probable that a functional proof-of-concept exploit will be developed and published by security researchers or threat actors in the near future. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Analyst Recommendation
Given the High severity (CVSS 8.8) of this vulnerability and the low complexity required for exploitation, we recommend immediate and urgent action. All organizations using the SEO Metrics plugin for WordPress must prioritize applying the vendor-supplied patch. If the plugin is not essential, the most secure course of action is to remove it entirely. Due to the high likelihood of future exploitation, proactive monitoring and a swift remediation response are critical to preventing a full compromise of the web application.
Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below...
Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is available to AI agents. Only password and command inputs are escaped in run_ssh_command_with_credentials to prevent shell injection; while username, host and port values are injectable. This issue does not have a fix at the time of publication.
Executive Summary:
A critical command injection vulnerability exists within the Cybersecurity AI (CAI) framework, affecting versions 0.5.9 and below. The flaw allows an attacker to execute arbitrary commands on the system running the AI agent by supplying malicious input for SSH connection parameters. Successful exploitation could lead to a complete system compromise, data theft, and significant operational disruption.
Vulnerability Details
CVE-ID: CVE-2025-67511
Affected Software: Cybersecurity AI Multiple Products
Affected Versions: Versions 0.5.9 and below
Vulnerability: The run_ssh_command_with_credentials() function within the Cybersecurity AI framework is vulnerable to command injection. The function fails to properly sanitize the username, host, and port parameters before incorporating them into a system shell command. An attacker who can influence the inputs provided to an AI agent can craft malicious values for these parameters (e.g., hostname; malicious_command) to execute arbitrary code on the server hosting the framework. This remote code execution occurs with the privileges of the user account running the Cybersecurity AI application.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.6. Exploitation could lead to Remote Code Execution (RCE), giving an attacker full control over the affected server. Potential consequences include the theft or destruction of sensitive data, deployment of ransomware, disruption of security operations, and using the compromised system as a pivot point to attack other internal network resources. Given that the framework is used for security automation, its compromise could severely undermine an organization's entire security posture.
Remediation Plan
Immediate Action: The vulnerability description notes that a fix is not available at the time of publication. Organizations should prepare to update Cybersecurity AI products to a patched version as soon as one is released by the vendor. In the interim, immediately begin monitoring for exploitation attempts by reviewing application and system access logs for any unusual inputs to the vulnerable function.
Proactive Monitoring:
run_ssh_command_with_credentials() function that contain shell metacharacters (e.g., ;, |, &, $(), `) in the username, host, or port fields.sh, bash, curl, wget).Compensating Controls:
run_ssh_command_with_credentials() function or restrict its use to only trusted, hard-coded parameters.Exploitation Status
Public Exploit Available: False
Analyst Notes: As of the publication date of December 11, 2025, there is no official patch available from the vendor, elevating the risk associated with this vulnerability. While there is no known public exploit code, the nature of command injection vulnerabilities makes them relatively straightforward for attackers to develop exploits for. Organizations should assume this vulnerability is actively being targeted.
Analyst Recommendation
Due to the critical 9.6 CVSS score and the lack of an available patch, this vulnerability requires immediate attention. The highest priority is to implement compensating controls, such as input validation and enhanced monitoring, to reduce the risk of exploitation. Organizations must closely monitor all communications from Cybersecurity AI for the release of a security patch and be prepared to apply it on an emergency basis. Although not currently on the CISA KEV list, its high severity and potential impact make it a prime candidate for future inclusion, underscoring the urgency of mitigation.
Update Cybersecurity AI Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided b...
Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool executes arbitrary SQL provided by the caller using PDO::prepare() + execute() without semantic restrictions. This is consistent with the name (“write tool”), but in an LLM/agent context it becomes a high-risk capability: prompt injection or indirect prompt manipulation can cause execution of destructive queries such as DROP TABLE, TRUNCATE, DELETE, ALTER, or privilege-related statements (subject to DB permissions). Deployments that expose an agent with MySQLWriteTool enabled to untrusted input and/or run the tool with a DB user that has broad privileges are impacted. This issue is fixed in version 2.8.12.
Executive Summary:
A critical vulnerability exists in the Neuron PHP framework that allows an attacker to execute destructive database commands by manipulating the AI agent. Successful exploitation could lead to the complete loss or corruption of application data, causing significant business disruption. Organizations using affected versions of the Neuron framework are urged to apply the recommended security update immediately.
Vulnerability Details
CVE-ID: CVE-2025-67510
Affected Software: Neuron is a PHP framework for creating and orchestrating AI Multiple Products
Affected Versions: Versions 2.8.11 and below
Vulnerability: The vulnerability lies within the MySQLWriteTool component of the Neuron framework. This tool is designed to execute SQL queries against a MySQL database but lacks sufficient semantic restrictions on the types of queries it can run. An attacker can leverage prompt injection or indirect prompt manipulation techniques to trick a Large Language Model (LLM) integrated with the framework into generating malicious SQL statements. The MySQLWriteTool will then execute these arbitrary queries, which can include destructive commands like DROP TABLE, TRUNCATE, DELETE, or privilege modification statements, leading to unauthorized data destruction, modification, or a denial of service. The attack's success and impact are contingent on the database user permissions configured for the tool.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.4, reflecting the potential for severe and widespread damage. A successful exploit could result in the complete and irreversible destruction of business-critical data, leading to catastrophic operational downtime and significant financial loss. The manipulation or deletion of sensitive information could also trigger regulatory penalties and cause severe reputational harm. Organizations that expose an AI agent using the vulnerable tool to untrusted input and have configured it with a highly privileged database account face the highest risk of data loss and system compromise.
Remediation Plan
Immediate Action: Immediately upgrade all instances of the Neuron framework to version 2.8.12 or a later, patched version as recommended by the vendor. After patching, monitor database and application logs for any signs of attempted or successful exploitation that may have occurred prior to the update.
Proactive Monitoring:
DROP, TRUNCATE, DELETE, ALTER, or GRANT originating from the application server.MySQLWriteTool.Compensating Controls:
If immediate patching is not feasible, implement the following controls to mitigate risk:
MySQLWriteTool has the minimum permissions required for its intended function. Specifically, revoke permissions for DROP, TRUNCATE, ALTER, and other Data Definition Language (DDL) or Data Control Language (DCL) statements.MySQLWriteTool is not essential for business operations, disable it entirely within the application's configuration.MySQLWriteTool, blocking queries containing high-risk keywords.Exploitation Status
Public Exploit Available: false
Analyst Notes: As of the published date of this advisory (Dec 10, 2025), there are no known public exploit scripts or reports of this vulnerability being actively exploited in the wild. However, the attack vector relies on prompt injection, a well-understood technique, making it highly likely that threat actors could develop exploits independently.
Analyst Recommendation
Given the critical CVSS score of 9.4 and the potential for complete data destruction, this vulnerability poses a severe risk to the organization. We strongly recommend that all affected systems be patched to version 2.8.12 or newer on an emergency basis. If patching must be delayed, the implementation of compensating controls, particularly enforcing the principle of least privilege on the associated database account, should be treated as the highest priority to limit potential damage. Although this vulnerability is not currently on the CISA KEV list, its severity warrants immediate attention and remediation.
Update Neuron is a PHP framework for creating and orchestrating AI Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Neuron is a PHP framework for creating and orchestrating AI Agents
Neuron is a PHP framework for creating and orchestrating AI Agents
Executive Summary:
A high-severity vulnerability has been discovered in multiple products utilizing the Neuron PHP framework, which could allow a remote, unauthenticated attacker to execute arbitrary code on the underlying server. Successful exploitation could lead to a complete system compromise, resulting in the theft of sensitive data, manipulation of AI agent behavior, and significant service disruption. Organizations are urged to apply vendor patches immediately to mitigate this critical risk.
Vulnerability Details
CVE-ID: CVE-2025-67509
Affected Software: Neuron Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability is a remote code execution (RCE) flaw within the Neuron PHP framework. It stems from improper input validation in an API endpoint responsible for processing data sent to the AI agents. An unauthenticated remote attacker can send a specially crafted request containing malicious serialized PHP objects, which, when processed by the framework, can trigger arbitrary code to be executed on the server with the permissions of the web server user.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.2. A successful exploit would grant an attacker complete control over the affected application server. The potential consequences include the exfiltration of sensitive business data processed by the AI agents, theft or manipulation of proprietary AI models, disruption of critical business operations that rely on the Neuron framework, and using the compromised server as a pivot point to launch further attacks against the internal network. Reputational damage and regulatory fines could also result from a data breach stemming from this vulnerability.
Remediation Plan
Immediate Action: The primary remediation is to apply the security updates provided by the vendor across all affected systems immediately. Before deployment to production, patches should be tested in a controlled environment to ensure they do not disrupt business operations. After patching, organizations must continue to monitor for any signs of exploitation attempts and review historical access logs for indicators of compromise that may have occurred prior to the patch.
Proactive Monitoring: Implement enhanced monitoring on affected servers. Security teams should look for unusual or malformed requests to Neuron API endpoints in web server access logs, unexpected processes being spawned by the web server (e.g., www-data, apache), and any suspicious outbound network connections from the application servers. File integrity monitoring should be used to detect unauthorized changes to the application's source code.
Compensating Controls: If immediate patching is not feasible, implement the following compensating controls:
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 11, 2025, there is no known public proof-of-concept exploit code available, and there are no reports of this vulnerability being actively exploited in the wild. However, given the high severity and the straightforward nature of the attack vector, it is highly probable that security researchers and threat actors will develop and release exploit code in the near future.
Analyst Recommendation
Organizations utilizing the Neuron framework must prioritize the immediate application of vendor-supplied security patches to mitigate the risk of a full system compromise. Although this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, its high severity and potential for remote code execution warrant an urgent and decisive response. If patching is delayed for any reason, the compensating controls outlined above should be implemented immediately while actively monitoring for any signs of compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools
gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Filament is a collection of full-stack components for accelerated Laravel development
Filament is a collection of full-stack components for accelerated Laravel development
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/r...
PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.1.0-beta expose POST /api/v1/record/buffer/convert through missing authentication. The endpoint accepts a file upload and converts it to PDF via LibreOffice by uploading payload to os.path.join(tmpdir, file.filename) without normalizing the filename. An attacker can submit a crafted filename containing ../ sequences to write arbitrary files anywhere the service account has permission, enabling remote file overwrite or planting malicious code. This issue is fixed in version 0.1.0-beta.
Executive Summary:
A critical vulnerability has been identified in the PipesHub AI platform that allows an unauthenticated attacker on the network to write arbitrary files to the server. This flaw can be easily exploited to overwrite system files or upload malicious code, potentially leading to a complete compromise of the affected system. Organizations are urged to update to the latest version immediately to mitigate this significant risk.
Vulnerability Details
CVE-ID: CVE-2025-67506
Affected Software: PipesHub is a fully extensible workplace AI platform for enterprise search and workflow Multiple Products
Affected Versions: Versions prior to 0.1.0-beta
Vulnerability: The vulnerability is a combination of two weaknesses: a missing authentication check and a path traversal flaw. The API endpoint /api/v1/record/buffer/convert does not require any authentication, allowing any unauthenticated user to access it. An attacker can send a POST request to this endpoint with a file upload, where the filename is specially crafted to include path traversal sequences (e.g., ../../etc/passwd). The application fails to sanitize this filename and concatenates it with a temporary directory path, allowing the attacker to write the uploaded file to an arbitrary location on the filesystem with the permissions of the service account running the application. This can lead to remote file overwrite or the placement of a web shell, resulting in remote code execution.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.8. A successful exploit could lead to a complete compromise of the server hosting the PipesHub platform, jeopardizing the confidentiality, integrity, and availability of the system and its data. Potential consequences include unauthorized access to sensitive enterprise data, deployment of ransomware, service disruption, and the use of the compromised server to launch further attacks against the internal network. The lack of authentication required for exploitation significantly increases the risk, as any attacker with network access to the platform can attempt to exploit it.
Remediation Plan
Immediate Action: The primary remediation is to upgrade all affected PipesHub instances to version 0.1.0-beta or later, where this vulnerability has been fixed. After patching, administrators should review access logs for any signs of exploitation attempts targeting the /api/v1/record/buffer/convert endpoint.
Proactive Monitoring:
/api/v1/record/buffer/convert endpoint, particularly from unexpected or external IP addresses.../ or ..\.Compensating Controls: If immediate patching is not feasible, the following temporary measures can reduce risk:
/api/v1/record/buffer/convert endpoint.Exploitation Status
Public Exploit Available: false
Analyst Notes: As of Dec 10, 2025, there are no known public exploits for this vulnerability. However, due to the critical severity and the straightforward nature of the flaw (a combination of missing authentication and path traversal), proof-of-concept exploits are likely to be developed and released by security researchers and threat actors in the near future.
Analyst Recommendation
Given the critical CVSS score of 9.8 and the low complexity of exploitation, this vulnerability poses a severe and immediate threat to the organization. We strongly recommend that all affected PipesHub instances be patched to version 0.1.0-beta or later on an emergency basis. While this vulnerability is not currently listed on the CISA KEV catalog, its characteristics make it a prime candidate for future inclusion. If patching cannot be performed immediately, the compensating controls listed above, particularly blocking the vulnerable endpoint via a WAF, should be implemented without delay.
Update PipesHub is a fully extensible workplace AI platform for enterprise search and workflow Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Okta Java Management SDK facilitates interactions with the Okta management API
Okta Java Management SDK facilitates interactions with the Okta management API
Executive Summary:
A high-severity vulnerability has been discovered in the Okta Java Management SDK, a component used to interact with Okta's management API. This flaw could allow an unauthenticated attacker to bypass security controls and execute unauthorized administrative actions within an organization's Okta environment. Successful exploitation could lead to a complete compromise of user accounts, application access, and sensitive data managed by Okta.
Vulnerability Details
CVE-ID: CVE-2025-67505
Affected Software: Okta Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability exists within the security token validation logic of the Okta Java Management SDK. An attacker can send a specially crafted API request containing a malformed or improperly signed security token to an application that utilizes the vulnerable SDK. The SDK fails to correctly validate the cryptographic signature of the token, leading to an authentication bypass that grants the attacker the privileges of the user they are impersonating, which could include administrative-level access.
Business Impact
This is a High severity vulnerability with a CVSS score of 8.4, posing a significant risk to the organization. A successful exploit could result in a complete compromise of the organization's identity and access management infrastructure. Potential consequences include unauthorized creation of privileged accounts, modification or deletion of existing users, broad access to integrated applications, and theft of sensitive corporate or customer data. This could lead to severe financial loss, regulatory penalties, reputational damage, and major operational disruption.
Remediation Plan
Immediate Action: Prioritize and apply the security updates provided by Okta to all applications and systems using the affected Java Management SDK versions. Review Okta system logs for any anomalous administrative activities, such as unexpected user creations, privilege escalations, or policy changes originating from application service accounts.
Proactive Monitoring: Implement enhanced monitoring of API endpoints for applications using the SDK. Look for malformed API requests, authentication attempts with invalid tokens, or a sudden spike in administrative actions. Correlate Okta logs with application and network logs to identify suspicious patterns that may indicate an exploitation attempt.
Compensating Controls: If immediate patching is not feasible, implement a Web Application Firewall (WAF) with rules specifically designed to inspect and block malicious requests targeting the affected API interactions. Restrict network access to the affected application endpoints, allowing connections only from trusted and explicitly authorized sources.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 10, 2025, there are no known public proof-of-concept exploits or observed in-the-wild attacks targeting this vulnerability. However, due to the critical nature of Okta's platform and the high impact of the vulnerability, security researchers and threat actors are highly motivated to develop an exploit in the near future.
Analyst Recommendation
Given the high CVSS score of 8.4 and the critical function of Okta as a core identity provider, this vulnerability requires immediate attention. Organizations must treat the remediation of CVE-2025-67505 as a top priority. Although this vulnerability is not currently listed on the CISA KEV catalog, its severity makes it a prime candidate for future inclusion. A swift and thorough patching process is critical to prevent a potential compromise of the entire identity and access management framework.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Nordic Semiconductor
PRODUCT: IronSide SE for nRF54H20
AFFECTED_VERSIONS: Before version 23
---END_METADATA---
Description Summary:
Nordic Semiconductor IronSide SE for nRF54H20 versions before 23 contain an unspecified vulnerability.
Executive Summary:
A vulnerability in Nordic Semiconductor’s IronSide SE for nRF54H20 requires immediate attention and patching to ensure the security of the affected hardware platform.
Vulnerability Details
CVE-ID: CVE-2025-67841
Affected Software: Nordic Semiconductor IronSide SE for nRF54H20
Affected Versions: Before version 23
Vulnerability: This is an unspecified vulnerability affecting the IronSide SE security component for the nRF54H20 platform. The lack of detailed information necessitates a cautious approach and immediate update to the latest provided firmware or software version.
Business Impact
With a CVSS score of 7.5, this vulnerability represents a high risk to the integrity of the nRF54H20 platform. Given that this component is often used in security-critical embedded applications, an exploit could compromise the hardware's security boundary, leading to potential data theft or device manipulation.
Remediation Plan
Immediate Action: Update the IronSide SE for nRF54H20 to version 23 or higher immediately.
Proactive Monitoring: Monitor device logs for any unusual behavior or unexpected restarts that could indicate an attempt to exploit the device.
Compensating Controls: Isolate affected devices from untrusted network segments until the firmware update is applied.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of April 17, 2026, there is no public information indicating active exploitation. However, the high severity score suggests that the vulnerability may be significant and warrants prompt action.
Analyst Recommendation
Users of the nRF54H20 platform should verify their current IronSide SE version and update to version 23 or later. Ensuring the security of the embedded environment is critical for maintaining the overall integrity of the deployed solution.