NVD disclosure day

Published threat advisories for August 4, 2025

CVE advisoryCRITICAL

CVE-2025-50341

Axelor SQL Injection Vulnerability Allows Data Exposure

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in the Axelor platform could allow an unauthenticated attacker to manipulate database queries via a specific parameter. This could potentially lead to the exposure of sensitive data or further system compromise. The affected technology is an ERP and BPM platform, commonly exposed to the in

CVE advisoryCRITICAL

CVE-2025-52239

ZKEACMS v4.1 Arbitrary File Upload Leading to Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical arbitrary file upload vulnerability in ZKEACMS allows for the execution of arbitrary code. This could impact the integrity and availability of the content management system, and it is a concern for publicly accessible web applications. Confirmation of usage and exposure assessment is necessary.

CVE advisoryCRITICAL

CVE-2025-51390

TOTOLINK N600R Command Injection Vulnerability in setWiFiWpsConfig.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A command injection vulnerability exists in TOTOLINK N600R router firmware via the `pin` parameter in the `setWiFiWpsConfig` function. This flaw could permit unauthenticated remote attackers to execute arbitrary commands on vulnerable devices, potentially impacting their configuration and network services if exposed. T

CVE advisoryKnown Exploit

CVE-2025-6205

DELMIA Apriso: Unauthorized Access Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A missing authorization vulnerability in DELMIA Apriso allows an attacker to gain privileged access. This impacts organizations using affected versions, potentially compromising data and business operations. The realistic business risk involves unauthorized access to sensitive information and disruption of manufacturin

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-6204

DELMIA Apriso Code Injection Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

Certain DELMIA Apriso versions are affected by a code injection vulnerability. This flaw could allow an attacker to execute arbitrary code, leading to system compromise and data manipulation. Affected organizations face risks to system integrity and data security.

• CISA KEV