Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
proof-of-concept-releasewidely-deployed-product-advisoryinternet-facing-service-vulnerabilityendpoint-software-vulnerability

Multiple High-Impact Vulnerabilities Disclosed Across Diverse Software Platforms

Updated 3mo agoFirst seen Dec 22, 202535 sources

A series of critical and high-severity vulnerabilities have been disclosed affecting a wide range of software products, including workflow automation tools, web applications, network devices, and desktop software. Notable issues include remote code execution (RCE) flaws in n8n, Lilac-Reloaded for Nagios, FileZilla Client, and AVideo, as well as privilege escalation vulnerabilities in products like Versa SASE Client, AspEmail, and ActFax. Several vulnerabilities allow unauthenticated attackers to upload arbitrary files, bypass authentication, or exploit weak session management, potentially leading to full system compromise or unauthorized access to sensitive data. Many of these vulnerabilities have public exploits available, increasing the risk of active exploitation in the wild.

Vendors have released patches for several of the affected products, and administrators are strongly advised to update to the latest versions or apply recommended mitigations. The vulnerabilities span a variety of attack vectors, including buffer overflows, improper input validation, insecure file upload mechanisms, and misconfigured authentication endpoints. Organizations should prioritize patching systems exposed to the internet and review access controls to limit the impact of potential exploitation. Immediate attention is warranted for products with critical CVSS scores and those with known public exploits.

Share:
Multiple High-Impact Vulnerabilities Disclosed Across Diverse Software Platforms
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

20 events from the most recent confirmed update back to the earliest known activity.

20 EVENTS
Dec 22, 20256mo ago

SecurityOnline reports newly surfaced flaws in Apache NiFi, Exim, and Dify

On December 22, 2025, SecurityOnline published separate reports on a deserialization-related data leak risk in Apache NiFi, a failed-patch-plus-SQL-injection issue leading to Exim heap overflows, and CVE-2025-63387 in Dify exposing system configuration data to anonymous users. These articles indicate public emergence of additional vulnerability disclosures on those products.

SecurityOnline amplifies n8n RCE risk in follow-up coverage

SecurityOnline published follow-up reporting on the critical n8n remote code execution vulnerability, emphasizing the potential for total server compromise. The article did not introduce a separate new incident but reflected growing public attention to the flaw after disclosure.

Dec 21, 20256mo ago

Tenda FH1201 SetIpBind overflow is publicly documented

CVE-2025-14995 was publicly disclosed for Tenda FH1201 firmware 1.2.0.14(408), describing a stack-based buffer overflow in the SetIpBind handler. The publication referenced public proof-of-concept code and urged users to update firmware.

Wordfence reports arbitrary file copy flaw in Contact Form 7 add-on

CVE-2025-14800 was published on December 21, 2025, for Redirection for Contact Form 7 up to version 3.2.7. Reported by security@wordfence.com, the flaw allows unauthenticated arbitrary file copy via move_file_to_upload and can enable remote file upload when allow_url_fopen is enabled.

Tenda FH1201/FH1206 webtypelibrary overflow is disclosed

CVE-2025-14994 was published for Tenda FH1201 and FH1206 routers, covering a stack-based buffer overflow in the webtypelibrary handler. The disclosure referenced released proof-of-concept exploits and recommended applying firmware patches.

Tenda AC18 SetDlnaCfg overflow is published with exploit in the wild claim

CVE-2025-14993 was published for a stack-based buffer overflow in the Tenda AC18 SetDlnaCfg handler. The advisory said a public proof-of-concept was available and stated the exploit was confirmed in the wild.

Tenda AC18 GetParentControlInfo overflow is publicly disclosed

CVE-2025-14992 was publicly disclosed for Tenda AC18 version 15.03.05.05, describing a stack-based buffer overflow in the GetParentControlInfo handler. The disclosure noted public proof-of-concept exploit availability and advised firmware updates.

Dec 20, 20256mo ago

VulnCheck discloses Versa SASE Client local privilege-escalation flaw

CVE-2025-34290 was disclosed on December 20, 2025, affecting Versa SASE Client for Windows versions 7.8.7 through 7.9.4. The issue combines improper privilege handling, a TOCTOU race, and symlink abuse to enable arbitrary folder deletion and potential SYSTEM-level compromise.

Flex Store Users unauthenticated privilege-escalation bug is published

CVE-2025-13619 was published for Flex Store Users up to version 1.1.0, describing a critical vulnerability that allows unauthenticated privilege escalation. The brief disclosure assigned a CVSS 9.8 score and warned of severe exploitation risk.

Wordfence reports unauthenticated file upload flaw in WooCommerce plugin

CVE-2025-13329 was published on December 20, 2025, for File Uploader for WooCommerce up to version 1.0.3. Reported by security@wordfence.com, the flaw allows unauthenticated arbitrary file upload through the add-image-data REST API endpoint and can lead to remote code execution.

TP-Link Tapo C200 local-network auth flaw is published

CVE-2025-14300 was published for the Tapo C200 V3, describing unauthenticated access to the connectAP API endpoint over the local network. The issue allows attackers on the same network to alter Wi-Fi settings and potentially cause denial of service, with TP-Link references and firmware updates noted.

Dec 19, 20256mo ago

n8n publishes critical expression-injection RCE and fixed versions

CVE-2025-68613 was disclosed for n8n, describing authenticated remote code execution through workflow expression injection in versions from 0.211.0 up to fixed releases 1.120.4, 1.121.1, and 1.122.0. The advisory urged immediate upgrades and noted temporary hardening measures were insufficient to fully remove risk.

Multiple VulnCheck-disclosed CVEs are published with public exploit details

On December 19, 2025, a large set of vulnerabilities were publicly disclosed, including flaws in FileZilla Client, LDAP Tool Box Self Service Password, Kimai, Flatnux, InnovaStudio WYSIWYG Editor, Ever Gauzy, AspEmail, Dotclear, ActFax, Arcsoft PhotoStudio, Lilac-Reloaded for Nagios, OCS Inventory NG, and BrainyCP. The disclosures described impacts ranging from remote code execution and account takeover to local privilege escalation, and many referenced public proof-of-concept exploits.

GT Edge AI Platform code injection flaw is published with patch guidance

CVE-2025-63665 was published for a critical code injection vulnerability affecting GT Edge AI Platform versions before v2.0.10-dev. The disclosure said public proof-of-concept exploits existed and directed users to upgrade to v2.0.10-dev or later.

Dive fixes Mermaid XSS-to-RCE issue in version 0.11.1

A critical stored XSS vulnerability in Dive's Mermaid rendering component, tracked as CVE-2025-66580, was documented as enabling remote code execution after user interaction. The issue was addressed in Dive version 0.11.1 and later, with advisories and PoCs published on GitHub.

VulnCheck discloses AVideo unauthenticated RCE flaw

CVE-2025-34433 was disclosed on December 19, 2025, for AVideo versions before 20.1, where a predictable installation salt can be recovered and used to achieve unauthenticated remote code execution. Public GitHub proof-of-concept code was referenced in the disclosure.

M-Files discloses session token exposure flaw and releases patches

M-Files published CVE-2025-13008, describing a vulnerability in M-Files Web that lets an authenticated attacker capture other users' session tokens. The vendor released fixes for affected M-Files Server branches and advised customers to upgrade.

Authentication bypass CVE-2025-52692 is published and CSA issues alert

CVE-2025-52692, a high-severity authentication bypass affecting unspecified products, was published as allowing access to some administrative functions via a crafted URL from the local network. The Singapore Cyber Security Agency issued an alert on the vulnerability.

Mintlify SSTI vulnerability is published with public GitHub PoCs noted

CVE-2025-67843 was published for a high-severity server-side template injection flaw in Mintlify Platform's MDX Rendering Engine before version 2025-11-15. The disclosure noted public proof-of-concept exploits on GitHub and advised updating and sanitizing MDX content.

Palantir reports and Apollo deploys fix for Glutton V1 auth bypass

Palantir coordinated disclosure of CVE-2024-49587, a missing-authentication flaw exposing Glutton V1 endpoints on Gotham stacks. Apollo automatically deployed a patch to all Apollo-managed Gotham instances to mitigate the issue.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

68 LINKEDOpen in app
Vulnerabilities
32 linked
Unauthenticated access to Dify /console/api/system-features endpointAuthentication bypass via crafted URL in administrative functions (CVE-2025-52692)SSTI in Mintlify Platform MDX Rendering Engine (pre-2025-11-15)Session token disclosure in M-Files Server (M-Files Web)Unauthenticated RCE in AVideo notify.ffmpeg.json.php via predictable installation saltStored XSS in Dive Mermaid renderer leading to RCE via malicious MCP server configUnauthenticated access to Glutton V1 service endpoints on Palantir Gotham stacksRCE via crafted JSON payload in GT Edge AI Community Edition Prompt window (pre-2.0.12)Stack-based buffer overflow in TOTOLINK T10 cstecgi.cgi loginAuthUrl handlingKimai 1.30.10 SameSite session cookie misconfiguration (session hijacking)Local Privilege Escalation via Insecure Service Binary Permissions in AspEmail 5.6.0.2 (EmailAgent)Host header injection in LDAP Tool Box Self Service Password 1.5.2 password reset token generationRCE via OS command injection in Lilac-Reloaded for Nagios 2.0.8 autodiscovery (nmap_binary)Local Privilege Escalation via Unquoted Service Path in OCS Inventory NG 2.3.0.0JWT authentication bypass via weak HMAC secret in Ever Gauzy v0.281.9Unrestricted file upload in InnovaStudio WYSIWYG Editor 5.4 (asset manager)DLL hijacking (TextShaping.dll) in FileZilla Client 3.63.1Authenticated RCE in n8n Workflow Expression EvaluationAuthenticated RCE via unrestricted .phar upload in Dotclear 2.25.3Authenticated RCE via crontab command injection in BrainyCP 1.0Authenticated arbitrary PHP file upload leading to RCE in Flatnux 2021-03.25Local Privilege Escalation via Unquoted Service Path in Arcsoft PhotoStudio 6.0.0.172 (ArcSoft Exchange Service)Local Privilege Escalation via Unquoted Service Path in ActFax 10.10 ActiveFaxServiceNTUnauthenticated connectAP API on Tapo C200 V3 HTTPS service (Wi‑Fi config change / DoS)Arbitrary file upload in File Uploader for WooCommerce (WordPress) via add-image-data REST endpointPrivilege Escalation in Flex Store Users WordPress Plugin <= 1.1.0LPE via Audit Log Export in Versa SASE Client for Windows 7.8.7–7.9.4Stack-based Buffer Overflow in Tenda AC18 /goform/GetParentControlInfoStack-based Buffer Overflow in Tenda AC18 /goform/SetDlnaCfgStack-based Buffer Overflow in Tenda FH1201/FH1206 /goform/webtypelibraryArbitrary file upload / file copy in Redirection for Contact Form 7 (WordPress) <= 3.2.7Stack-based Buffer Overflow in Tenda FH1201 /goform/SetIpBind
Affected products
10 linked
NifiDotclearFilezilla ClientFlatnuxFh1201 FirmwareTapo C200PhotostudioKimaiN8nT10
Organizations
26 linked
TendaVulnCheckGitHubWordfenceDotclearFilezilla-ProjectPalantir TechnologiesKimaiPersitsM-FilesFlatnuxcvefeed.ioMITRETP-LinkTotolinkWordpressN8nVulDBArcsoftCyber Security Agency of SingaporeWwbnMintlifyOpenagentplatformInnovaStudioEver GauzyUploadcare
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Multiple High-Impact Vulnerabilities Disclosed Across Diverse Software Platforms | Mallory