2025 Vulnerability Reports
CVE-2025-8088: WinRAR Path Traversal Vulnerability Analysis of the critical WinRAR path traversal vulnerability used in the wild to achieve code execution.
CVE-2025-66389: GitHub Copilot Workspace Traversal & File-Handler Exfiltration Technical root cause and exploit analysis of CVE-2025-66389, an unauthorized filesystem access and data exfiltration flaw in GitHub Copilot 1.372.0 via the fetch_webpage file-handler URI scheme.
CVE-2025-64504: Langfuse Cross-Organization Member Enumeration Analysis of a broken access control vulnerability in Langfuse allowing authenticated users to enumerate members and invitation lists across organizations.
CVE-2025-61882: Zero-Day RCE in Oracle E-Business Suite (BI Publisher / Concurrent Processing) Authoritative technical teardown of CVE-2025-61882: critical remote code execution (CVSS 9.8) in Oracle EBS actively exploited by GRACEFUL SPIDER for corporate database exfiltration and ransomware extortion.
CVE-2025-60710 - Elevation of Privilege in Host Process for Windows Tasks Deep dive into the EoP vulnerability in Windows AI Recall scheduled tasks allowing SYSTEM privilege escalation.
CVE-2025-59528: Flowise CustomMCP Node JavaScript Function Constructor Remote Code Execution In-depth technical analysis of CVE-2025-59528 in Flowise AI Workflow Builder: CWE-94: Improper Control of Generation of Code ('Code Injection'), attack surface, exploitation vectors, detection rules, and remediation.
CVE-2025-59470: PostgreSQL Remote Code Execution via Operator Role in Veeam Backup & Replication Detailed technical analysis of CVE-2025-59470 in Veeam Backup & Replication (KB4716): SQL injection allowing Backup and Tape Operators to achieve RCE as the postgres service user.
CVE-2025-59469: Arbitrary File Write as Root by Operators in Veeam Backup & Replication Technical deep dive into CVE-2025-59469 in Veeam Backup & Replication (KB4716): arbitrary file write flaw allowing Backup and Tape Operators to write files as root.
CVE-2025-59468: PostgreSQL Remote Code Execution via Malicious Password Parameter in Veeam Backup & Replication In-depth technical breakdown of CVE-2025-59468 in Veeam Backup & Replication (KB4716): SQL injection within credential management triggering RCE under the postgres database user.
CVE-2025-59417: Lobe Chat lobeArtifact SVG dangerouslySetInnerHTML XSS to RCE In-depth technical root cause and exploit chain analysis of CVE-2025-59417, a stored XSS and remote code execution vulnerability in Lobe Chat's lobeArtifact SVG renderer.
CVE-2025-58434: FlowiseAI Unauthenticated Full Account Takeover Critical analysis of a password reset token leak in FlowiseAI allowing complete unauthenticated account takeover.
CVE-2025-5777: OOB Memory Disclosure and MFA Session Hijacking in Citrix NetScaler ADC & Gateway (CitrixBleed 2) Technical reference dossier on CVE-2025-5777 ('CitrixBleed 2'): out-of-bounds memory read flaw (CWE-125) in NetScaler ADC and Gateway enabling unauthenticated session hijacking and complete MFA bypass.
CVE-2025-55182: 'React2Shell' β Pre-Auth Deserialization RCE in Meta React Server Components Technical reference dossier on CVE-2025-55182 ('React2Shell'): deserialization of untrusted data (CWE-502) in react-server-dom-webpack and React Server Functions allowing unauthenticated remote code execution.
CVE-2025-55125: Root Command Injection via Backup Configuration in Veeam Backup & Replication Comprehensive technical analysis of CVE-2025-55125 in Veeam Backup & Replication (KB4716): OS command injection (CWE-78) allowing operators to achieve root code execution.
CVE-2025-54795: Claude Code Echo Command Injection and Approval Prompt Bypass via Untrusted Context In-depth technical analysis of CVE-2025-54795 in Claude Code Agentic CLI: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), attack surface, exploitation vectors, detection rules, and remediation.
CVE-2025-54794: Claude Code Working Directory Sandbox Escape via Path Prefix Matching In-depth technical analysis of CVE-2025-54794 in Claude Code Agentic CLI: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), attack surface, exploitation vectors, detection rules, and remediation.
CVE-2025-53844: FortiOS Out-of-Bounds Write via Compromised Fabric Devices In-depth technical analysis of CVE-2025-53844 in Fortinet FortiOS: an out-of-bounds write vulnerability (CWE-787) allowing authenticated low-privileged attackers controlling connected FortiAP, FortiSwitch, or FortiExtender units to execute unauthorized code on the core FortiGate appliance.
CVE-2025-53773: GitHub Copilot RCE via Prompt Injection In-depth forensic and architectural analysis of CVE-2025-53773, a critical Remote Code Execution vulnerability in GitHub Copilot driven by Indirect Prompt Injection and workspace settings hijacking.
CVE-2025-53770: Insecure Deserialization RCE in Microsoft SharePoint Server (ToolShell) Authoritative technical teardown of CVE-2025-53770: untrusted deserialization (CWE-502) mass zero-day (ToolShell) exploited by Linen Typhoon, Violet Typhoon, and Storm-2603 to deploy Warlock ransomware.
CVE-2025-52970: Access Control Bypass and Privilege Escalation in Fortinet FortiWeb Technical reference dossier on CVE-2025-52970: improper handling of parameters (CWE-233) in Fortinet FortiWeb management interface allowing unauthenticated remote attackers to gain administrative privileges.
CVE-2025-5277: Command Injection in AWS MCP Server via Prompt-Coerced Tool Execution In-depth technical analysis of CVE-2025-5277 (CVSS 9.6, HTS 94), an OS command injection vulnerability in aws-mcp-server abused via indirect prompt injection to achieve arbitrary host execution and AWS cloud credential compromise.
CVE-2025-52573: iOS Simulator MCP Server ui_tap Command Injection Technical root cause and exploit analysis of CVE-2025-52573, a Command Injection vulnerability in the ios-simulator-mcp server prior to 1.3.3 caused by unsafe child_process.exec usage in the ui_tap tool.
CVE-2025-50105: Privilege Escalation and Workflow Tampering in Oracle E-Business Suite (Universal Work Queue) Technical reference dossier on CVE-2025-50105: access control flaw (CWE-284 / CWE-862) in Oracle Universal Work Queue Work Provider Administration allowing low-privileged authenticated users to tamper with enterprise workflows.
CVE-2025-49704: Remote Code Injection in Microsoft SharePoint Server Comprehensive technical analysis of CVE-2025-49704: improper control of code generation (CWE-94) in Microsoft SharePoint Server, chained with CVE-2025-49706 by Linen Typhoon and Violet Typhoon.
CVE-2025-49150: Cursor AI Editor Automatic JSON Schema Download Data Exfiltration In-depth vulnerability analysis of CVE-2025-49150 in Cursor AI Editor: silent out-of-band data exfiltration via automatic JSON schema downloads triggered by prompt-injected coding agents.
CVE-2025-49113: Authenticated RCE via PHP Deserialization in Roundcube Webmail (upload.php) Technical reference dossier on CVE-2025-49113: deserialization of untrusted data flaw (CWE-502) via the _from parameter in upload.php allowing authenticated users to execute arbitrary system code on enterprise webmail servers.
CVE-2025-47277: vLLM Distributed KV-Cache PyNcclPipe Remote Code Execution Comprehensive architectural and forensic analysis of CVE-2025-47277, an unauthenticated RCE vulnerability in vLLM's distributed KV-cache transfer layer via unsafe pickle deserialization and 0.0.0.0 network binding.
CVE-2025-42944: Unauthenticated Java Deserialization RCE in SAP NetWeaver AS Java (RMI-P4) Technical reference dossier on CVE-2025-42944: insecure deserialization flaw (CWE-502) in SAP NetWeaver AS Java RMI-P4 module allowing unauthenticated remote command execution with sapadm privileges.
CVE-2025-39964: Linux Kernel Crypto AF_ALG Concurrent Write Race Condition Detailed analysis of CVE-2025-39964, a concurrency race condition in the Linux kernel crypto user API (af_alg_sendmsg) added to the CISA KEV Catalog in September 2026.
CVE-2025-39682: Linux Kernel kTLS Receive Path Zero-Length Record Use-After-Free Privilege Escalation In-depth technical analysis of CVE-2025-39682 in the Linux kernel in-tree TLS subsystem (kTLS): logic flaw in tls_sw_recvmsg handling zero-length records leading to socket buffer use-after-free and local root escalation (CISA KEV).
CVE-2025-32724: Remote Denial of Service and System Crash in Windows LSASS via RPC Technical reference dossier on CVE-2025-32724: uncontrolled resource consumption (CWE-400) in Windows Local Security Authority Subsystem Service (LSASS) enabling unauthenticated remote attackers to trigger process crashes and forced domain controller reboots.
CVE-2025-32711: M365 Copilot 'EchoLeak' Zero-Click IPI Technical analysis of EchoLeak (CVE-2025-32711), a critical Zero-Click Indirect Prompt Injection vulnerability in Microsoft 365 Copilot leading to massive data exfiltration.
CVE-2025-3248: Langflow Unauthenticated Code Validation Python exec() Remote Code Execution In-depth technical analysis of CVE-2025-3248 in Langflow Visual AI Builder: CWE-94: Improper Control of Generation of Code ('Code Injection'), attack surface, exploitation vectors, detection rules, and remediation.
CVE-2025-32433: Pre-Authentication Command Execution in Erlang/OTP SSH Server Technical reference dossier on CVE-2025-32433: missing authentication for critical function (CWE-306) in Erlang/OTP SSH server enabling unauthenticated remote command execution on host systems.
CVE-2025-30733: Pre-Authentication Memory Leak in Oracle Database Server (RDBMS Listener) Technical reference dossier on CVE-2025-30733: information disclosure flaw (CWE-200 / CWE-125) in Oracle Database RDBMS Listener allowing unauthenticated remote extraction of memory buffers and session metadata via Oracle Net (TNS).
CVE-2025-29927: Middleware Authorization Bypass via x-middleware-subrequest Header in Next.js Technical reference dossier on CVE-2025-29927: improper authorization flaw (CWE-285) in Vercel Next.js allowing unauthenticated remote attackers to bypass security middleware checks by injecting the x-middleware-subrequest header.
CVE-2025-29824: SYSTEM Privilege Escalation in Windows CLFS Driver (Use-After-Free) Comprehensive technical analysis of CVE-2025-29824: Use-After-Free (CWE-416) in clfs.sys exploited as a zero-day by ransomware affiliates to obtain NT AUTHORITY\SYSTEM privileges.
CVE-2025-29635: Command injection vulnerability in D-Link DIR-823X router firmware Command injection vulnerability in D-Link DIR-823X router firmware.
CVE-2025-26319: Flowise Arbitrary File Upload and Directory Traversal Remote Code Execution In-depth technical analysis of CVE-2025-26319 in Flowise AI Workflow Builder: CWE-434: Unrestricted Upload of File with Dangerous Type, attack surface, exploitation vectors, detection rules, and remediation.
CVE-2025-25257: Unauthenticated SQL Injection in Fortinet FortiWeb Management Interface Technical reference dossier on CVE-2025-25257: critical SQL injection flaw (CWE-89) in the HTTP/HTTPS management interface of Fortinet FortiWeb allowing unauthenticated remote command or SQL execution.
CVE-2025-25249: Fortinet FortiOS cw_acd CAPWAP Heap Overflow to Unauthenticated RCE Technical root cause, heap layout exploitation, and forensic analysis of CVE-2025-25249 (CISA KEV) in Fortinet FortiOS cw_acd daemon actively exploited with PivotC2.
CVE-2025-24813: RCE via Partial PUT Requests and Session Deserialization in Apache Tomcat Technical reference dossier on CVE-2025-24813: path equivalence (CWE-44) and insecure deserialization (CWE-502) in Apache Tomcat enabling remote unauthenticated code execution via partial HTTP PUT requests.
CVE-2025-24472: Super-Admin Authentication Bypass in Fortinet FortiOS & FortiProxy (CSF Proxy) Technical reference dossier on CVE-2025-24472: authentication bypass using an alternate path (CWE-288) in Fortinet FortiOS and FortiProxy CSF proxy component allowing remote attackers to achieve super-admin privileges.
CVE-2025-24054: NTLM Hash Disclosure and Coerced Authentication in Windows (.library-ms) Authoritative technical teardown of CVE-2025-24054: external control of filename or path (CWE-73) in Windows Explorer (.library-ms) enabling forced SMB authentication and NetNTLMv2 hash harvesting.
CVE-2025-23304: NVIDIA NeMo Framework RCE Deep dive into CVE-2025-23304, a critical RCE vulnerability in NVIDIA NeMo Framework demonstrating the severe risks of AI Supply Chain attacks via malicious model files.
CVE-2025-22457: Subsequent Pre-Auth Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA) Technical reference dossier on CVE-2025-22457: second critical stack buffer overflow flaw (CWE-121) in Ivanti Connect Secure gateways enabling unauthenticated remote code execution with root privileges.
CVE-2025-21333: Windows Kernel Privilege Escalation via Hyper-V VSP (Heap Overflow) Authoritative teardown of CVE-2025-21333: heap-based buffer overflow (CWE-122) in Windows Hyper-V NT Kernel Integration VSP (vskrnlintvsp.sys) enabling arbitrary kernel read/write.
CVE-2025-20393: Unauthenticated Root RCE in Cisco Secure Email Gateway (Spam Quarantine) Authoritative technical teardown of CVE-2025-20393: improper input validation (CWE-20) in Cisco AsyncOS Spam Quarantine exploited in targeted zero-day attacks by state actor UAT-9686.
CVE-2025-20352: SNMP Stack Buffer Overflow in Cisco IOS and IOS XE (DoS & RCE) Comprehensive technical analysis of CVE-2025-20352: stack-based buffer overflow (CWE-121) in Cisco IOS/IOS XE SNMP subsystem causing device crashes and arbitrary root execution.
CVE-2025-20281: Unauthenticated Root RCE in Cisco Identity Services Engine (ISE) API Authoritative technical teardown of CVE-2025-20281: command injection (CWE-74) in Cisco ISE ERS API allowing unauthenticated remote root execution and full Network Access Control (NAC) compromise.
CVE-2025-20188: Arbitrary File Upload and Root RCE in Cisco IOS XE WLC via Hard-Coded JWT Authoritative technical teardown of CVE-2025-20188 (Horizon3.ai): hard-coded JWT credentials (CWE-798) and path traversal (CWE-22) on Cisco Catalyst 9800 controllers enabling unauthenticated root execution.
CVE-2025-0282: Pre-Authentication Root RCE via Stack Buffer Overflow in Ivanti Connect Secure (ICS / IPS / ZTA) Technical reference dossier on CVE-2025-0282: stack-based buffer overflow (CWE-121) in the web service of Ivanti Connect Secure, Policy Secure, and ZTA Gateways enabling unauthenticated remote code execution with root privileges.