NVD disclosure day

Published threat advisories for September 16, 2025

CVE advisoryCRITICAL

CVE-2025-34186

Ilevia EVE X1/X5 Server could allow an external attacker to gain full system access.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An external attacker can bypass authentication on Ilevia EVE X1/X5 Server to gain full system access, potentially modifying or stealing sensitive data. This matters to the business as it could lead to unauthorized access and control over critical systems.

CVE advisoryCRITICAL

CVE-2025-56557

Tuya Smart Life App Matter Protocol Unprivileged Control Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in the Tuya Smart Life App allows unprivileged control of Matter devices via the Matter protocol, potentially enabling unauthorized actions or access. Organizations using this app may face risks related to the integrity and availability of connected smart home devices.

CVE advisoryCRITICAL

CVE-2025-57119

Online Library Management System Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A privilege escalation vulnerability exists in the Online Library Management System's `adminlogin.php` component. An unauthenticated attacker could exploit this flaw to gain administrative privileges, potentially leading to unauthorized access and modification of library data if the system is network-accessible.

CVE advisoryCRITICAL

CVE-2025-7744

Dolusoft Omaspot SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in Dolusoft Omaspot allows attackers to execute arbitrary SQL commands by sending crafted data. This could potentially lead to unauthorized access, modification, or deletion of sensitive information stored in the application's database. It is important to determine if this software is in u

CVE advisoryCRITICAL

CVE-2025-4688

SINAV.LINK Exam Result Module SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability exists in the SINAV.LINK Exam Result Module, allowing network-accessible manipulation of database queries. This could lead to unauthorized access, modification, or deletion of sensitive data. The relevance of this module within the environment needs confirmation.