IBM Concert 1
Description
IBM Concert 1
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Search and filter 18466 vulnerabilities with AI analyst insights
IBM Concert 1
IBM Concert 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
IBM Engineering Systems Design Rhapsody 9
IBM Engineering Systems Design Rhapsody 9
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
IBM Engineering Systems Design Rhapsody 9
IBM Engineering Systems Design Rhapsody 9
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Microsoft Windows SMB Client Improper Access Control Vulnerability - Active in CISA KEV catalog.
Microsoft Windows SMB Client Improper Access Control Vulnerability - Active in CISA KEV catalog.
FEDERAL DEADLINE: November 9, 2025 (21 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: November 9, 2025 (21 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Deadline: November 9, 2025
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network
Insufficient UI warning of dangerous operations in Remote Desktop Client allows an unauthorized attacker to perform spoofing over a network
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to a...
APTIOV contains vulnerabilities in the BIOS where a privileged user may cause “Write-what-where Condition” and “Exposure of Sensitive Information to an Unauthorized Actor” through local access
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro s...
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
IBM Concert 1
IBM Concert 1
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
IBM InfoSphere Information Server 11
IBM InfoSphere Information Server 11
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper input validation for some Intel QuickAssist Technology before version 2
Improper input validation for some Intel QuickAssist Technology before version 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Thermo Fisher Scientific ePort through 3
Thermo Fisher Scientific ePort through 3
Executive Summary:
A high-severity vulnerability has been identified in multiple Thermo Fisher Scientific ePort products. This flaw could allow a remote, unauthenticated attacker to execute arbitrary code and gain full control of affected systems, posing a significant risk of data compromise, operational disruption, and loss of integrity for connected scientific instruments.
Vulnerability Details
CVE-ID: CVE-2025-32992
Affected Software: ePort Multiple Products
Affected Versions: Versions up to and including 3
Vulnerability: This vulnerability is an unauthenticated remote code execution (RCE) flaw. An attacker can exploit this by sending a specially crafted network packet to the management interface of a vulnerable ePort device. Due to improper input validation in the device's network service, this packet can trigger a buffer overflow, allowing the attacker to execute arbitrary code with system-level privileges without requiring any prior authentication or user interaction.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.5. Successful exploitation could have a severe impact on business operations, particularly in research and laboratory environments. An attacker could steal sensitive research data, manipulate experimental results, or cause a denial-of-service condition by taking critical equipment offline. The compromise of these systems could lead to significant financial loss, reputational damage, and a loss of intellectual property.
Remediation Plan
Immediate Action: Apply vendor-supplied security updates to all affected ePort systems immediately. After patching, review system and access logs for any signs of compromise that may have occurred prior to the update.
Proactive Monitoring: Implement enhanced monitoring for affected devices. Scrutinize network traffic for unusual patterns or connections from untrusted IP addresses. Monitor system logs for unexpected reboots, new user accounts, or unauthorized commands, and configure alerts for any anomalous activity.
Compensating Controls: If immediate patching is not feasible, isolate the affected ePort devices on a segmented network with strict firewall rules, restricting access to only trusted administrative hosts. Deploy an Intrusion Prevention System (IPS) with signatures capable of detecting and blocking exploit attempts targeting this vulnerability.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of August 18, 2025, there are no known public exploits or active exploitation campaigns targeting this vulnerability. However, given the high severity and low complexity of exploitation, it is highly probable that threat actors will develop and deploy exploits in the near future.
Analyst Recommendation
Given the high CVSS score of 8.5 and the potential for complete system compromise, this vulnerability presents a critical risk to the organization. Although this CVE is not currently listed on the CISA KEV catalog, its severity warrants immediate attention. We strongly recommend that all affected Thermo Fisher Scientific ePort systems are patched on a priority basis. If patching cannot be completed immediately, implement the suggested compensating controls to reduce the attack surface and mitigate risk.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A two-step attack targeting the RESTful API in N2WS Backup & Recovery enables remote code execution. This critical flaw is resolved in version 4.4.0.
A two-step attack targeting the RESTful API in N2WS Backup & Recovery enables remote code execution. This critical flaw is resolved in version 4.4.0.
---METADATA---
VENDOR: N2WS
PRODUCT: Backup & Recovery
AFFECTED_VERSIONS: Versions before 4.4.0
---END_METADATA---
Description Summary:
A two-step attack targeting the RESTful API in N2WS Backup & Recovery enables remote code execution. This critical flaw is resolved in version 4.4.0.
Executive Summary:
N2WS Backup & Recovery is susceptible to a critical remote code execution vulnerability via its RESTful API, allowing attackers to compromise backup infrastructure.
Vulnerability Details
CVE-ID: CVE-2025-32991
Affected Software: N2WS Backup & Recovery
Affected Versions: Versions before 4.4.0
Vulnerability: The vulnerability involves a multi-stage exploit chain targeting the application's RESTful API. By performing a "two-step" attack, an unauthenticated or low-privileged remote attacker can bypass security controls to execute arbitrary code on the underlying server.
Business Impact
The impact of Remote Code Execution (RCE) on a backup and recovery platform is catastrophic. An attacker could delete backups, exfiltrate sensitive data, or deploy ransomware across the recovery environment, effectively neutralizing the organization's disaster recovery capabilities. The CVSS score of 9.0 justifies the critical severity due to the potential for total loss of system control.
Remediation Plan
Immediate Action: Upgrade N2WS Backup & Recovery to version 4.4.0 or later immediately to close the vulnerable API endpoints.
Proactive Monitoring: Review API access logs for unusual patterns, specifically focusing on sequential requests to REST endpoints from unrecognized IP addresses.
Compensating Controls: Place the N2WS management interface behind a VPN or a Zero Trust Network Access (ZTNA) solution to limit API exposure to trusted internal users only.
Exploitation Status
Public Exploit Available: No
Analyst Notes: As of Mar 25, 2026, there is no public information indicating active exploitation of this vulnerability. However, backup solutions are frequent targets for sophisticated threat actors looking to disable recovery options before a secondary attack.
Analyst Recommendation
Protecting backup infrastructure is a fundamental security requirement. Because this vulnerability allows for full system takeover via the API, the update to version 4.4.0 is mandatory. Security teams should prioritize this patch to ensure the integrity of their data protection and recovery environment.
Update Unknown Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability - Active in CISA KEV catalog.
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability - Active in CISA KEV catalog.
FEDERAL DEADLINE: May 3, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: May 3, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Deadline: May 3, 2026
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
baserCMS is a website development framework
baserCMS is a website development framework
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
SSH Tectia Server before 6
SSH Tectia Server before 6
Executive Summary:
A high-severity vulnerability has been identified in Tectia SSH Server products, specifically versions prior to 6.0. This flaw, tracked as CVE-2025-32942, could allow a remote attacker to compromise the server, potentially leading to unauthorized access to sensitive systems and data. Organizations are urged to apply the vendor-provided security updates immediately to mitigate the significant risk of a security breach.
Vulnerability Details
CVE-ID: CVE-2025-32942
Affected Software: Tectia Multiple Products
Affected Versions: All versions of SSH Tectia Server prior to version 6.
Vulnerability: The vulnerability exists within the SSH Tectia Server software. While specific technical details of the flaw have not been disclosed, the assigned CVSS score of 7.2 indicates a high-impact vulnerability that can likely be exploited by a remote attacker without authentication. An attacker could potentially send a series of specially crafted packets or authentication requests to the affected server to trigger the flaw, which may result in unauthorized access, privilege escalation, or a denial-of-service condition.
Business Impact
This vulnerability is rated as high severity with a CVSS score of 7.2. Tectia SSH servers are often used for secure remote administration and file transfers for critical business systems. Successful exploitation could grant an attacker a foothold into the corporate network, leading to severe consequences such as data breaches, theft of sensitive intellectual property, installation of ransomware, or disruption of essential business operations. The compromise of a central administrative tool like an SSH server poses a significant risk to the confidentiality, integrity, and availability of the organization's data and infrastructure.
Remediation Plan
Immediate Action: The primary remediation is to apply the security updates provided by the vendor immediately. Administrators should upgrade all vulnerable instances of SSH Tectia Server to version 6.0 or a later patched version. Following the update, closely monitor for any signs of exploitation attempts and review SSH server access logs for anomalous activity preceding the patch.
Proactive Monitoring: Implement enhanced monitoring of network traffic to and from affected servers. Security teams should look for unusual connection patterns, repeated failed login attempts from unknown IP addresses, or connections using non-standard clients. Review system and authentication logs for unexpected user authentications, privilege escalations, or commands being executed.
Compensating Controls: If immediate patching is not feasible, implement compensating controls to reduce the attack surface. Restrict access to the SSH server management interface to a limited set of trusted IP addresses using firewall rules or network access control lists (ACLs). Enforce multi-factor authentication (MFA) for all SSH access to provide an additional layer of security against unauthorized access attempts.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of October 2, 2025, there are no known public proof-of-concept exploits or active attacks targeting this vulnerability. However, vulnerabilities in widely used remote access software like SSH servers are attractive targets for threat actors. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.
Analyst Recommendation
Given the high severity (CVSS 7.2) of this vulnerability and its potential impact on critical infrastructure, we strongly recommend that organizations prioritize the immediate patching of all affected Tectia SSH Server instances. Although there is no evidence of active exploitation at this time, the risk of a future exploit being developed is high. Proactive remediation is the most effective strategy to prevent a potential compromise of your organization's secure remote access infrastructure.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2
An issue was discovered in Kaseya Rapid Fire Tools Network Detective through 2
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Dell PowerFlex Manager, version(s) <=4
Dell PowerFlex Manager, version(s) <=4
---METADATA---
VENDOR: Dell
PRODUCT: PowerFlex Manager
AFFECTED_VERSIONS: Dell PowerFlex Manager (Appliance): 0 up to (excluding) IC 48.378.00/IC 48.383.00; Dell PowerFlex Manager (Rack): 0 up to (excluding) 3.7.8.0/3.8.3.0; Dell PowerFlex Manager: 0 through 4.6.2
CONFIDENCE: high
MISSING: none
---END_METADATA---
Description Summary:
A directory listing vulnerability in Dell PowerFlex Manager allows unauthenticated remote attackers to access sensitive information through improper configuration.
Executive Summary:
A directory listing vulnerability in Dell PowerFlex Manager permits unauthenticated remote attackers to access sensitive information, posing a significant information disclosure risk.
Vulnerability Details
CVE-ID: CVE-2025-32750
Affected Software: Dell PowerFlex Manager
Affected Versions: Dell PowerFlex Manager (Appliance) < IC 48.378.00 or IC 48.383.00; Dell PowerFlex Manager (Rack) < 3.7.8.0 or 3.8.3.0; Dell PowerFlex Manager versions 0 through 4.6.2.
Vulnerability: This is an exposure of information through directory listing (CWE-548), which is exploitable by an unauthenticated remote attacker via the network.
Business Impact
The vulnerability allows unauthorized parties to view sensitive file structures and potentially access configuration data, which could be leveraged to facilitate further attacks. With a CVSS score of 7.5 (High), this represents a significant risk to confidentiality, especially given the ease of exploitation over the network without requiring authentication.
Remediation Plan
Immediate Action: Update Dell PowerFlex Manager to the versions specified in the vendor security advisories (DSA-2025-435 and DSA-2025-434).
Proactive Monitoring: Audit web server access logs for unusual directory traversal patterns or unauthorized requests for directory listings.
Compensating Controls: Use a Web Application Firewall (WAF) to block requests that attempt to list directories or access restricted file paths.
Exploitation Status
Public Exploit Available: No (exploit_available: false)
Analyst Notes: As of May 22, 2026, there is no public information indicating active exploitation or a public proof-of-concept for this vulnerability. The vulnerability is highly automatable but currently shows no evidence of being weaponized in the wild.
Analyst Recommendation
Due to the unauthenticated nature of this vulnerability and its network-accessible vector, immediate patching is strongly recommended. Administrators should review the linked Dell security advisories to ensure all components are updated to the appropriate, non-vulnerable versions.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Validation of Specified Quantity in Input vulnerability in ThemesGrove WP SmartPay
Improper Validation of Specified Quantity in Input vulnerability in ThemesGrove WP SmartPay
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slide...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion
Executive Summary:
A high-severity vulnerability has been identified in multiple RadiusTheme products, specifically within the Testimonial Slider And Showcase Pro plugin. This flaw, a Local File Inclusion (LFI), allows an unauthenticated attacker to trick the application into including and executing unintended files from the server. Successful exploitation could lead to sensitive information disclosure, such as viewing configuration files and system passwords, or potentially a full compromise of the web server.
Vulnerability Details
CVE-ID: CVE-2025-32657
Affected Software: RadiusTheme Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability is a Local File Inclusion (LFI) caused by an Improper Control of Filename for an Include/Require Statement in the PHP code. An attacker can manipulate an input parameter, likely a URL parameter, to include directory traversal sequences (e.g., ../). This forces the PHP include or require function to load and process a file from an arbitrary location on the server's filesystem, granting the attacker access to read sensitive files that are normally not accessible.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 7.5. Exploitation could have a significant business impact, including the exposure of sensitive data like database credentials, application source code, and system user information. This data breach could lead to further system compromise, reputational damage, and regulatory fines. The ability to read server files can also facilitate more complex attacks, potentially leading to a complete server takeover and disruption of business operations.
Remediation Plan
Immediate Action: Apply vendor security updates immediately across all affected installations. After patching, administrators should monitor for any signs of post-patch exploitation attempts and thoroughly review historical access logs for indicators of compromise that may have occurred before the patch was applied.
Proactive Monitoring: Monitor web server access logs for suspicious requests containing directory traversal patterns (../), absolute file paths (e.g., /etc/passwd), or other file inclusion payloads. Implement file integrity monitoring on critical application and system files to detect unauthorized changes. Monitor for unusual PHP error messages which may indicate failed LFI attempts.
Compensating Controls: If immediate patching is not feasible, deploy a Web Application Firewall (WAF) with rules specifically designed to detect and block LFI and directory traversal attacks. Harden the PHP environment by disabling allow_url_include and configuring a restrictive open_basedir path to limit the locations from which files can be included. Ensure the web server process runs with the lowest possible user privileges.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of the publication date, October 23, 2025, there are no known public exploits or active exploitation campaigns targeting this vulnerability. However, vulnerabilities of this type are frequently and quickly weaponized by threat actors after disclosure. Organizations should assume that exploitation will occur and prioritize remediation accordingly.
Analyst Recommendation
Given the high CVSS score of 7.5 and the critical risk of information disclosure and server compromise, we strongly recommend that organizations apply the vendor-provided security patches to all affected RadiusTheme products as the highest priority. Although this vulnerability is not currently listed on the CISA KEV list, its nature makes it an attractive target. Proactive monitoring and the implementation of compensating controls, such as a WAF, are advised to provide layered defense and mitigate risk until patching is complete.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows SQL Injection
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows SQL Injection
Apply vendor patches immediately. Review database access controls and enable query logging.
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard. This issue affects Material Dashboard: from n/a t...
Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard. This issue affects Material Dashboard: from n/a through 1.4.6.
---METADATA---
VENDOR: Hossein
PRODUCT: Material Dashboard
AFFECTED_VERSIONS: 1.4.6 and earlier
CONFIDENCE: high
MISSING: patch
---END_METADATA---
Description Summary:
Hossein Material Dashboard is susceptible to a weak password recovery mechanism, which may allow attackers to hijack user accounts through the forgotten password process.
Executive Summary:
A critical flaw in the password recovery mechanism of Hossein Material Dashboard could allow unauthorized attackers to gain full control over user accounts.
Vulnerability Details
CVE-ID: CVE-2025-32486
Affected Software: Hossein Material Dashboard
Affected Versions: 1.4.6 and earlier
Vulnerability: The application implements a weak password recovery mechanism that can be exploited by an attacker to reset or bypass authentication for arbitrary user accounts. This typically involves predictable tokens or insufficient verification steps during the password reset workflow.
Business Impact
A CVSS score of 9.8 indicates a critical risk. Unauthorized account takeover can lead to the theft of sensitive data, unauthorized administrative actions within the dashboard, and potential compromise of the underlying system, resulting in severe reputational and operational damage.
Remediation Plan
Immediate Action: Update to the latest version of the Material Dashboard immediately to rectify the password recovery logic.
Proactive Monitoring: Review account recovery logs and password reset request patterns for signs of automated or bulk reset attempts targeting multiple user accounts.
Compensating Controls: If a patch is unavailable, temporarily disable the "forgot password" functionality or implement a manual, out-of-band verification process for password resets until a secure update is deployed.
Exploitation Status
Public Exploit Available: Not stated
Analyst Notes: As of Sep 9, 2025, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw, the potential for exploitation is high.
Analyst Recommendation
Account recovery mechanisms are a frequent target for attackers due to their ability to provide high-level access without requiring prior credentials. All users of the Material Dashboard should verify their version and apply the required updates immediately to mitigate the risk of account takeover.
Update Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0
A memory corruption vulnerability exists in the BMPv3 Image Decoding functionality of the SAIL Image Decoding Library v0
Executive Summary:
A high-severity memory corruption vulnerability has been identified in the SAIL Image Decoding Library, affecting multiple products that use this component to process BMPv3 images. Successful exploitation could allow an attacker to execute arbitrary code on a vulnerable system by tricking a user into opening a specially crafted image file, potentially leading to a full system compromise. Organizations are urged to apply vendor patches immediately to mitigate this significant risk.
Vulnerability Details
CVE-ID: CVE-2025-32468
Affected Software: memory Multiple Products
Affected Versions: SAIL Image Decoding Library v0. See vendor advisory for specific affected products and versions.
Vulnerability: The vulnerability is a memory corruption flaw within the function responsible for decoding BMPv3 image files. An attacker can create a malicious BMPv3 image with malformed headers or data sections that, when processed by the vulnerable library, cause a buffer overflow. This allows the attacker to write data outside of the intended memory buffer, which can be leveraged to overwrite critical program data, crash the application (Denial of Service), or execute arbitrary code with the same privileges as the user or service running the application.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.8. A successful exploit could have severe consequences for the business, including the complete compromise of affected workstations or servers. An attacker could leverage this access to steal sensitive data, deploy ransomware, install persistent backdoors for long-term access, or use the compromised system to pivot further into the corporate network. The direct business risks include data breaches, financial loss, reputational damage, and operational disruption if critical systems are impacted.
Remediation Plan
Immediate Action:
Proactive Monitoring:
Compensating Controls:
Exploitation Status
Public Exploit Available: false
Analyst Notes:
As of August 25, 2025, there are no known public proof-of-concept exploits or active exploitation campaigns targeting this vulnerability. However, memory corruption vulnerabilities in widely used libraries are attractive targets for threat actors, and exploit development is highly probable. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.
Analyst Recommendation
Given the high CVSS score of 8.8 and the potential for remote code execution, this vulnerability poses a significant risk to the organization. We strongly recommend that all system administrators prioritize the immediate identification of affected assets and the deployment of vendor-supplied patches. Although there is no evidence of active exploitation at this time, the severity of the flaw warrants urgent attention to prevent future compromise. Organizations should treat this vulnerability with the same priority as those on the CISA KEV list.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot op...
Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.
Update Sudo before Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
Deadline: October 19, 2025
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A memory corruption vulnerability exists in Foxit Reader 2025
A memory corruption vulnerability exists in Foxit Reader 2025
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.
Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.
FEDERAL DEADLINE: April 2, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: April 2, 2026 (13 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Deadline: April 2, 2026
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
In maybeShowDialog of ControlsSettingsDialogManager
In maybeShowDialog of ControlsSettingsDialogManager
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack
In multiple locations, there is a possible privilege escalation due to a tapjacking/overlay attack
Update to patched version immediately. Review user permissions and access controls.
In onStart of BiometricEnrollIntroduction
In onStart of BiometricEnrollIntroduction
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In onActivityResult of VoicemailSettingsActivity
In onActivityResult of VoicemailSettingsActivity
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In updateState of ContentProtectionTogglePreferenceController
In updateState of ContentProtectionTogglePreferenceController
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In startSpaActivityForApp of SpaActivity
In startSpaActivityForApp of SpaActivity
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In multiple locations, there is a possible memory corruption due to a use after free
In multiple locations, there is a possible memory corruption due to a use after free
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In showDismissibleKeyguard of KeyguardService
In showDismissibleKeyguard of KeyguardService
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In multiple functions of Session
In multiple functions of Session
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In multiple functions of Session
In multiple functions of Session
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In multiple functions of PickerDbFacade
In multiple functions of PickerDbFacade
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In multiple functions of AppRestrictionsFragment
In multiple functions of AppRestrictionsFragment
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In appendFrom of Parcel
In appendFrom of Parcel
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In onCommand of ActivityManagerShellCommand
In onCommand of ActivityManagerShellCommand
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In getCallingAppName of Shared
In getCallingAppName of Shared
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In onCreate of MediaProjectionPermissionActivity
In onCreate of MediaProjectionPermissionActivity
Executive Summary:
A high-severity vulnerability in the MediaProjectionPermissionActivity component could allow a malicious application to bypass user consent prompts and capture screen content.
Vulnerability Details
CVE-ID: CVE-2025-32322
Affected Software: onCreate Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: A flaw exists in the onCreate function of the MediaProjectionPermissionActivity. This component is responsible for managing user permissions for screen recording. The vulnerability likely involves improper initialization or state handling that a malicious application could exploit to gain screen capture capabilities without explicit user approval.
Business Impact
With a CVSS score of 7.8, this vulnerability poses a serious risk to data confidentiality. A successful exploit would allow an attacker to silently record all activity on a user's screen, capturing sensitive information such as login credentials, private messages, and confidential documents. This could lead to account takeovers, financial fraud, and significant data breaches.
Remediation Plan
Immediate Action: Immediately apply the security updates from the vendor to correct the permission-handling flaw.
Proactive Monitoring: Monitor for unexpected screen recording or media projection activity on endpoints. Endpoint security solutions may be able to detect applications attempting to use screen capture APIs without proper permissions.
Compensating Controls: Restrict the installation of applications from untrusted sources. Educate users about the dangers of granting unnecessary permissions to applications, particularly for screen sharing or accessibility services.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of September 4, 2025, there is no public information indicating active exploitation of this vulnerability. However, the ability to bypass user consent for screen recording makes this an extremely attractive target for spyware.
Analyst Recommendation
This is a critical privacy and security vulnerability requiring immediate remediation. The vendor patch must be deployed urgently across all affected systems to prevent unauthorized screen capture and protect sensitive user data.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In isSafeIntent of AccountTypePreferenceLoader
In isSafeIntent of AccountTypePreferenceLoader
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In System UI, there is a possible way to view other users' images due to a confused deputy
In System UI, there is a possible way to view other users' images due to a confused deputy
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands
A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arbitrary OS commands
Executive Summary:
A high-severity vulnerability has been identified in multiple products from the vendor 'remote'. This flaw allows an attacker on the internet, without any credentials, to bypass authentication and execute arbitrary commands on the affected system, potentially leading to a complete system takeover and data breach.
Vulnerability Details
CVE-ID: CVE-2025-3232
Affected Software: remote Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability exists within a specific API route that fails to properly enforce authentication controls. A remote, unauthenticated attacker can send a specially crafted request to this endpoint to bypass security checks. This allows the attacker to then pass malicious operating system (OS) commands, which are executed on the underlying server with the privileges of the application's service account.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 7.5. Successful exploitation could lead to a complete system compromise, allowing an attacker to steal sensitive data, install malware or ransomware, disrupt critical business operations, or use the compromised system as a pivot point to attack other internal network resources. The direct business risks include regulatory fines from data breaches, significant financial loss from operational downtime or ransomware payments, and severe reputational damage.
Remediation Plan
Immediate Action: Apply vendor security updates immediately across all affected systems. Prioritize patching for internet-facing systems to reduce the attack surface. After patching, review access logs and system logs for any signs of compromise that may have occurred before the patch was applied.
Proactive Monitoring: Monitor web server and application logs for unusual or malformed requests to API endpoints, particularly any that do not follow expected patterns. Monitor for unexpected outbound network connections from affected servers and look for suspicious process execution or file creation on the host systems, which could indicate a successful compromise.
Compensating Controls: If immediate patching is not feasible, restrict network access to the affected API endpoints using a Web Application Firewall (WAF) or network firewall rules, allowing connections only from trusted IP addresses. If possible, disable the vulnerable API route if it is not essential for business operations.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of December 26, 2025, there are no known public exploits or active exploitation campaigns targeting this vulnerability. However, given the low complexity and high impact of an unauthenticated remote code execution flaw, it is highly probable that a functional exploit will be developed by security researchers or threat actors in the near future.
Analyst Recommendation
Given the High severity (CVSS 7.5) of this unauthenticated remote code execution vulnerability, immediate action is required. Although this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, its characteristics make it an attractive target for future exploitation. Organizations are strongly advised to prioritize the application of vendor-supplied patches to all affected systems to prevent potential system compromise.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In Skia, there is a possible out of bounds write due to a heap buffer overflow
In Skia, there is a possible out of bounds write due to a heap buffer overflow
Executive Summary:
A high-severity vulnerability has been discovered in Skia, a widely used 2D graphics library. This flaw, a heap buffer overflow, can be exploited by an attacker using a specially crafted image or graphic, potentially allowing them to crash the application or execute arbitrary code on the affected system. This could lead to a complete system compromise, data theft, or denial of service.
Vulnerability Details
CVE-ID: CVE-2025-32318
Affected Software: In Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability is a heap-based buffer overflow within the Skia graphics library. The flaw occurs when the library processes improperly formed graphical data. An attacker can create a malicious file (e.g., an image, font, or web element) that causes the software to write data past the boundaries of an allocated memory buffer on the heap. By carefully crafting the overflow data, an attacker can overwrite critical program data or function pointers, leading to arbitrary code execution with the same permissions as the user running the affected application. Exploitation typically requires a user to open a malicious file or visit a compromised website that renders the malicious graphic.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.8. Successful exploitation could have a significant negative impact on the business. The primary risk is a full system compromise, allowing an attacker to execute arbitrary code, which could lead to data exfiltration of sensitive corporate information, deployment of ransomware, or the use of the compromised system as a pivot point for further network intrusion. Additionally, exploitation could cause the affected application to crash, resulting in a denial of service (DoS) condition that disrupts user productivity and business operations. A public breach stemming from this vulnerability could also lead to significant reputational damage and loss of customer trust.
Remediation Plan
Immediate Action: Organizations must apply vendor security updates immediately across all affected products. System administrators should prioritize patching internet-facing systems and workstations used by high-risk users. Following patch deployment, security teams should monitor for any signs of exploitation attempts by reviewing application crash logs, security alerts, and network traffic for anomalous behavior.
Proactive Monitoring: Security teams should configure monitoring and alerting for signs of compromise. This includes monitoring for unexpected application crashes, particularly in browsers or other software known to use Skia. Endpoint Detection and Response (EDR) solutions should be monitored for alerts related to memory corruption, suspicious process creation originating from graphics-rendering applications, or unexpected network connections from these processes.
Compensating Controls: If immediate patching is not feasible, organizations should implement compensating controls. This includes using application control to prevent the execution of untrusted software, ensuring that exploit protection features like Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are enabled, and educating users on the risks of opening files or visiting links from unverified sources. Restricting access to vulnerable applications or isolating them within the network can also limit the potential impact.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of September 5, 2025, there is no known public proof-of-concept exploit code, and the vulnerability is not reported to be actively exploited in the wild. However, due to the high severity score and the widespread use of the Skia library in major software products like web browsers and mobile operating systems, it is highly likely that threat actors will reverse-engineer the patch and develop exploits.
Analyst Recommendation
This is a critical vulnerability that requires immediate attention. Due to the high potential for remote code execution (CVSS 8.8), we strongly recommend that organizations treat the remediation of CVE-2025-32318 as an emergency. All available vendor patches should be deployed without delay, prioritizing critical and internet-exposed systems. Although this vulnerability is not yet on the CISA KEV list, its severity and the ubiquity of the Skia library make it a prime target for future exploitation. Proactive patching is the most effective defense against potential attacks.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In UsageEvents of UsageEvents
In UsageEvents of UsageEvents
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
In createIntentsList of PackageParser
In createIntentsList of PackageParser
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP...
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mojoomla WPCHURCH allows PHP Local File Inclusion
Executive Summary:
A high-severity vulnerability has been identified in multiple Mojoomla WPCHURCH products, tracked as CVE-2025-32304. This flaw, a Local File Inclusion, allows an unauthenticated attacker to trick the application into reading and displaying the contents of sensitive files on the server. Successful exploitation could lead to the exposure of confidential data, system credentials, and application source code, posing a significant risk to data integrity and system security.
Vulnerability Details
CVE-ID: CVE-2025-32304
Affected Software: Mojoomla WPCHURCH Multiple Products
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: The vulnerability is a Local File Inclusion (LFI) caused by an Improper Control of a Filename used in a PHP include() or require() statement. An attacker can exploit this by manipulating an input parameter, such as a URL query string, to include path traversal sequences (e.g., ../../..). This forces the application to navigate the server's file system and include a file of the attacker's choosing, which is then processed or rendered to the attacker. For example, an attacker could request a file like /etc/passwd to enumerate system users or access configuration files containing database credentials, leading to a significant information disclosure.
Business Impact
This vulnerability is rated as High severity with a CVSS score of 8.1. The primary business impact is the potential for a severe data breach through the unauthorized disclosure of sensitive information. Consequences of exploitation include the theft of customer data, intellectual property, or internal credentials, which could facilitate further attacks. Such an incident could result in significant reputational damage, loss of customer trust, regulatory fines for non-compliance with data protection standards, and substantial financial costs associated with incident response and recovery.
Remediation Plan
Immediate Action: Apply the security updates released by Mojoomla WPCHURCH across all affected products without delay. Concurrently, security teams must actively monitor for signs of attempted exploitation and conduct a thorough review of web server access and error logs for any suspicious requests matching the attack pattern.
Proactive Monitoring: Security teams should monitor web server access logs for requests containing path traversal sequences (e.g., ../, %2e%2e%2f, ..%2f) in URL parameters. Implement alerts for attempts to access common sensitive files such as /etc/passwd, /proc/self/environ, or application configuration files (e.g., wp-config.php, .env). Monitor for unexpected PHP errors in logs, which could indicate failed file inclusion attempts.
Compensating Controls: If immediate patching is not feasible, deploy a Web Application Firewall (WAF) with a robust ruleset to detect and block path traversal attacks. Additionally, harden the server environment by enforcing strict file system permissions to limit the files accessible by the web server user. Further restrict PHP's capabilities by configuring open_basedir to limit the file paths that PHP can access.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of January 7, 2026, there are no known public proof-of-concept exploits or active exploitation campaigns targeting this vulnerability. However, Local File Inclusion vulnerabilities are generally well-understood and can be straightforward to exploit once a vector is identified. The absence of public exploits should not be interpreted as a low risk, as threat actors may develop them independently.
Analyst Recommendation
Given the high severity (CVSS 8.1) of this vulnerability and its potential for critical information disclosure, immediate patching is the most effective course of action. While this vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, its potential impact warrants urgent attention. Organizations using affected Mojoomla WPCHURCH products should prioritize the deployment of vendor-supplied patches and implement the recommended monitoring and compensating controls to mitigate the significant risk of a data breach.
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.Thi...
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.
Executive Summary:
A critical vulnerability has been identified in the Mojoomla WPCHURCH plugin, which could allow a remote, unauthenticated attacker to access and manipulate the website's database. Successful exploitation could lead to the theft of sensitive information, such as user data and credentials, or a complete compromise of the affected website's data integrity.
Vulnerability Details
CVE-ID: CVE-2025-32303
Affected Software: Mojoomla WPCHURCH
Affected Versions: All versions up to and including 2.7.0
Vulnerability:
The vulnerability is a Blind SQL Injection, which results from the application's failure to properly sanitize user-supplied input before incorporating it into an SQL query. An attacker can submit specially crafted input to a vulnerable parameter, which is then executed by the back-end database. Because this is a "blind" SQL injection, the attacker does not receive direct output from the database in the web response. Instead, they must infer data by observing the application's behavior—such as differences in response times or content—to true/false questions posed to the database, allowing them to exfiltrate data piece by piece.
Business Impact
This vulnerability is rated as critical severity with a CVSS score of 9.3. Exploitation could have a severe impact on the business, leading to a significant data breach. An attacker could exfiltrate the entire contents of the database, including sensitive user information, administrator credentials, and other confidential data. This could result in direct financial loss, severe reputational damage, loss of customer trust, and potential regulatory fines for non-compliance with data protection standards.
Remediation Plan
Immediate Action:
Immediately update the Mojoomla WPCHURCH plugin to the latest version available (newer than 2.7.0) which addresses this vulnerability. After patching, it is crucial to monitor for any signs of post-patch exploitation attempts and review historical access logs for indicators of compromise that may have occurred before the patch was applied.
Proactive Monitoring:
Implement enhanced monitoring of web server and database logs. Look for suspicious requests containing SQL keywords (e.g., UNION, SELECT, SLEEP(), ' OR '1'='1') or time-based queries aimed at the application. Monitor for an unusual number of requests or unexpectedly long database response times, as these can be indicators of a Blind SQL injection attack in progress.
Compensating Controls:
If immediate patching is not feasible, implement a Web Application Firewall (WAF) with a ruleset designed to detect and block SQL injection attacks. Additionally, ensure the database user account associated with the web application operates with the principle of least privilege, limiting an attacker's ability to read from sensitive tables or modify the database structure.
Exploitation Status
Public Exploit Available: false
Analyst Notes:
As of January 7, 2026, there are no known public exploits or active exploitation campaigns targeting this vulnerability. However, SQL injection is a well-understood vulnerability class, and proof-of-concept exploits can be developed quickly by threat actors.
Analyst Recommendation
Given the critical severity (CVSS 9.3) of this vulnerability, immediate action is required. Organizations using the affected versions of the Mojoomla WPCHURCH plugin must prioritize applying the vendor-supplied patch to mitigate the risk of a data breach. Although this vulnerability is not currently listed on the CISA KEV catalog, its high potential for impact makes it an attractive target for attackers. Proactive remediation is essential to prevent potential data compromise and protect sensitive organizational and customer data.
Update Improper Neutralization of Special Elements used in an SQL Command Multiple Products to the latest version. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: IBM
PRODUCT: Concert 1
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
A security vulnerability in IBM Concert 1 could allow for unauthorized actions or data exposure, impacting the overall security posture of the application.
Executive Summary:
IBM Concert 1 is affected by a high-severity vulnerability that could lead to unauthorized access or the compromise of application data if left unaddressed.
Vulnerability Details
CVE-ID: CVE-2025-33088
Affected Software: IBM Concert 1
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability affects IBM Concert 1, a platform used for application management and automation. The flaw likely resides in the application's handling of user requests or session management, though specific technical parameters should be verified via the IBM advisory.
Business Impact
A successful exploit could result in unauthorized users accessing sensitive management data or interfering with automated workflows. The CVSS score of 7.4 justifies a High severity rating, as it represents a significant threat to the confidentiality and integrity of the application management lifecycle.
Remediation Plan
Immediate Action: Administrators should immediately update IBM Concert 1 to the latest patched version provided by IBM to close the identified security gap.
Proactive Monitoring: Monitor application logs for unusual activity, specifically focusing on unauthorized administrative actions or unexpected data exports.
Compensating Controls: Implement network segmentation to isolate the IBM Concert management server and use a Web Application Firewall (WAF) to filter malicious traffic.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 18, 2026, there is no public information indicating active exploitation of this vulnerability. The vulnerability's impact is significant enough that proactive patching is the recommended course of action.
Analyst Recommendation
With a CVSS score of 7.4, this vulnerability presents a clear and present risk to the IBM Concert environment. Organizations relying on this platform for automation and management should prioritize the application of the primary remediation update to ensure continued secure operations.