10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical exposure
CVE-2025-0987Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd.
CVSS 9.9
Potential privilege escalation to admin/root
New critical disclosure (CVSS 9.9) — high severity with a short public awareness window before exploit material typically surfaces.
Critical exposure
CVE-2025-11953React Native Community CLI OS Command Injection
CVSS 9.8
New critical React Native Community CLI Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2025-63451Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php.
CVSS 9.8
New critical Car-booking-system-php Project Car-booking-system-php SQL Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.