VulnSea

Daily digest

Wednesday 8 October 2025

A heavy day: 83 new CVEs, well above the recent average of about 33. Of those, 4 critical and 26 high. 4 arrived with exploitation evidence or public exploit code already attached. jhumanj was the most-affected vendor with 9.

83
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 83 published.

CVE-2025-61913Critical· 9.9
1y ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit …

▾ Midnightflowiseai · flowiseEPSS 13%via NVD
CVE-2025-11418Critical· 9.8
1y ago

A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1

A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mit_ssid_…

▾ Midnighttenda · ch22_firmwareEPSS 6.7%via NVD
CVE-2025-11423Critical· 9.8
1y ago

A vulnerability was found in Tenda CH22 1.0.0.1

A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory corruption. The attack is possible to be…

▾ Midnighttenda · ch22_firmwareEPSS 0.86%via NVD
CVE-2025-10587Critical· 9.8
1y ago

The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient prep…

The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient prep…

▾ MidnightEPSS 0.39%via NVD
CVE-2025-11444High· 8.8
1y ago

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506

A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such manipulation of the argu…

▾ Twilighttotolink · n600r_firmwareEPSS 1.0%via NVD
CVE-2025-48981High· 8.6
1y ago

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.

An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.

▾ TwilightEPSS 0.12%via NVD
CVE-2025-61787High· 8.1
1y ago

Deno is a JavaScript, TypeScript, and WebAssembly runtime

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly sp…

▾ Twilightdeno · denoEPSS 2.1%via NVD
CVE-2025-53967High· 8.0
1y ago

Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl com…

Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system commands via a crafted HTTP POST request with shell metacharacters in input that is used by a fetchWithRetry curl com…

▾ TwilightEPSS 5.8%via NVD
CVE-2025-10494High· 8.1
1y ago

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation when deleting profile pictures in all versions up to, and including, 1.4.89. …

▾ TwilightEPSS 0.49%via NVD
CVE-2025-10635High· 7.7
1y ago

The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks

The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing subscribers and above to perform SQL injection attacks

▾ TwilightEPSS 0.27%via NVD
CVE-2025-11171Medium· 5.3PoC
1y ago

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9

The Chartify – WordPress Chart Plugin for WordPress is vulnerable to Missing Authentication for Critical Function in all versions up to, and including, 3.5.9. This is due to the plugin registering an unauthenticated AJAX action that disp…

▾ TwilightEPSS 0.41%via NVD
CVE-2025-11507High· 7.3
1y ago

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1

A weakness has been identified in PHPGurukul Beauty Parlour Management System 1.1. The impacted element is an unknown function of the file /admin/search-invoices.php. This manipulation of the argument searchdata causes sql injection. The…

▾ Twilightphpgurukul · beauty_parlour_management_systemEPSS 0.42%via NVD

Most-affected vendors

By CVEs published in the period.