Critical exposure
CVE-2025-25257 Fortinet FortiWeb SQL Injection
- CVSS 9.8
New critical Fortinet FortiWeb SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
New critical Fortinet FortiWeb SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical Totolink A3300r Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
New critical disclosure (CVSS 9.8) — high severity with a short public awareness window before exploit material typically surfaces.
CISA KEV — confirmed in-the-wild exploitation.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
Nothing flagged in this category for this digest.
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker cou...
Fortinet FortiWeb SQL Injection
nbcio-boot v1.0.3 was discovered to contain a SQL injection vulnerability via the userIds parameter at /sys/user/deleteRecycleBin.
Totolink A3300R V17.0.0cu.596_B20250515 was found to contain a command injection vulnerability in the sub_4197C0 function via the mac and...
Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
GoldenDict 1.5.0 and 1.5.1 has an exposed dangerous method that allows reading and modifying files when a user adds a crafted dictionary...
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions.
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions.
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions.
Laravel Livewire Code Injection