| ID | Severity | Title | AI Score | Found | Status |
|---|---|---|---|---|---|
| ZDS-2025-0142 | CRITICAL9.8 | Prototype pollution via crafted JSON chunk EPSS 96%POC NOKEVEXPLOITED NOW | 97 | 12h ago | DISCLOSED |
| ZDS-2025-0141 | HIGH8.4 | Pickle deserialization backdoor in tokenizer.bin EPSS 80%POC NONO-KEVNOT EXPLOITED | 95 | 1d ago | DISCLOSED |
| ZDS-2025-0140 | HIGH7.8 | World-writable /var/run permits LPE in sidecar pattern EPSS 66%POC NOKEVNOT EXPLOITED | 82 | 3d ago | PATCHED |
| ZDS-2025-0139 | CRITICAL9.4 | Path traversal in tool/read_file allows host FS read EPSS 91%POC NOKEVEXPLOITED NOW | 96 | 4d ago | DISCLOSED |
| ZDS-2025-0138 | MEDIUM6.3 | Typo-squat shipping postinstall miner EPSS 57%POC NONO-KEVNOT EXPLOITED | 88 | 6d ago | DISCLOSED |
| ZDS-2025-0137 | HIGH7.4 | Prompt-injectable cookie exfiltration EPSS 67%POC NONO-KEVNOT EXPLOITED | 89 | 8d ago | EMBARGOED |
| ZDS-2025-0136 | MEDIUM6.1 | Embedded Lambda layer phones home with prompts EPSS 51%POC NONO-KEVNOT EXPLOITED | 81 | 10d ago | DISCLOSED |
| ZDS-2025-0135 | LOW3.7 | Default entrypoint logs PG password to stdout on retry EPSS 27%POC NONO-KEVNOT EXPLOITED | 69 | 12d ago | PATCHED |
| ecosystem | exposure score | critical | artifacts | mean ai |
|---|---|---|---|---|
| Docker | 477 | 1 | 3 | 82 |
| npm | 432 | 1 | 4 | 88 |
| Hugging Face | 290 | 0 | 3 | 85 |
| MCP | 276 | 2 | 3 | 92 |
| rank | advisory | active risk | business impact | threat context |
|---|---|---|---|---|
| #1 | ZDS-2025-0142 CRITICAL · CWE-1321 | 168 | 52 | EPSS 96%no poc |
| #2 | ZDS-2025-0128 CRITICAL · CWE-78 | 165 | 52 | EPSS 92%no poc |
| #3 | ZDS-2025-0129 CRITICAL · CWE-798 | 163 | 51 | EPSS 91%no poc |
| #4 | ZDS-2025-0139 CRITICAL · CWE-22 | 162 | 50 | EPSS 91%no poc |
| #5 | ZDS-2025-0141 HIGH · CWE-502 | 139 | 46 | EPSS 80%no poc |
| #6 | ZDS-2025-0131 HIGH · CWE-22 | 132 | 45 | EPSS 74%no poc |
| #7 | ZDS-2025-0137 HIGH · CWE-200 | 124 | 42 | EPSS 67%no poc |
| #8 | ZDS-2025-0140 HIGH · CWE-732 | 123 | 44 | EPSS 66%no poc |
Block known exploit paths and isolate impacted workloads.
Confirm exploitability with PoC and telemetry evidence.
Prioritize patch rollout by exposure score and blast radius.
Issue advisory updates and mitigation instructions.
curl -s https://zerodayshield.local/feeds/zero-days.rss
curl -s https://zerodayshield.local/api/zero-days?severity=CRITICAL&ecosystem=npm
query LatestCritical {
advisories(limit: 20, severity: CRITICAL) {
id
title
cvss
cwe
discoveredAt
}
}Official Redis image, Alpine variant.
Streaming JSON / NDJSON parser with backpressure support.
Production-ready PostgreSQL container by Bitnami.
All-in-one build toolchain image.
Tar/zip extraction with streaming API.
Quantized Whisper Turbo for CPU inference.