NVD disclosure day

Published threat advisories for November 26, 2025

CVE advisoryKnown Exploit

CVE-2025-62593

Ray Remote Code Execution Vulnerability Via Browser Attack

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical remote code execution vulnerability exists in the Ray AI compute engine affecting developers. Exploitation is possible through Firefox and Safari by tricking a developer into visiting a malicious website or encountering malvertising, potentially leading to unauthorized code execution within the development e

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-50433

Imonnit User Account Takeover Via Password Reset

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A vulnerability in imonnit.com's password reset mechanism enables malicious actors to escalate privileges and take over user accounts. This flaw is critical because it allows for the compromise of arbitrary user accounts without prior access, potentially impacting system data and user account integrity if the platform

CVE advisoryCRITICAL

CVE-2025-65669

Classroomio allows unauthorized students to delete courses.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An issue exists in classroomio where student accounts can delete courses from the Explore page without authorization. This bypasses intended administrative restrictions and could disrupt educational operations through unauthorized removal of course content. The affected technology is classroomio, specifically version 0