Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Dlink Dir-825 Firmware: public exploit or PoC linked (Buffer Overflow)
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Active exploit activity
CVE-2025-10370A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0.
Public exploit or PoC available
Exploit activity linked
Sourcefabric Rpi-jukebox-rfid cross-site scripting now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Active exploit activity
CVE-2025-10666A security flaw has been discovered in D-Link DIR-825 up to 2.10.
Public exploit or PoC available
Exploit activity linked
Dlink Dir-825 Firmware Buffer Overflow now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2026-25142SandboxJS is a JavaScript sandboxing library.
CVSS 10
Remote code execution exposure
New critical Nyariv Sandboxjs RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.