VulnSea

Daily digest

Thursday 9 October 2025

A heavy day: 127 new CVEs, well above the recent average of about 42. Of those, 16 critical and 42 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. juniper was the most-affected vendor with 36.

127
New CVEs
16
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 127 published.

CVE-2025-11371High· 7.5CISA KEVPoC
1y ago

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been obser…

▾ Abyssalgladinet · centrestackEPSS 92%via NVD
CVE-2025-59246Critical· 9.8
1y ago

Azure Entra ID Elevation of Privilege Vulnerability

Azure Entra ID Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · entra_idEPSS 7.7%via NVD
CVE-2025-11539Critical· 9.9
1y ago

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability

Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to sav…

▾ MidnightEPSS 0.64%via NVD
CVE-2025-7634Critical· 9.8
1y ago

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated…

▾ MidnightEPSS 0.80%via NVD
CVE-2025-7526Critical· 9.8
1y ago

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versi…

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versi…

▾ MidnightEPSS 0.92%via NVD
CVE-2025-35051Critical· 9.8
1y ago

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges

Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. Ac…

▾ Midnightnewforma · project_centerEPSS 0.84%via NVD
CVE-2025-35050Critical· 9.8
1y ago

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges

Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpo…

▾ Midnightnewforma · project_centerEPSS 0.92%via NVD
CVE-2025-11522Critical· 9.8
1y ago

The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7

The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elate…

▾ MidnightEPSS 0.56%via NVD
CVE-2025-10586Critical· 9.8
1y ago

The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa…

The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient prepa…

▾ MidnightEPSS 0.50%via NVD
CVE-2025-59218Critical· 9.6
1y ago

Azure Entra ID Elevation of Privilege Vulnerability

Azure Entra ID Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · entra_idEPSS 0.66%via NVD
CVE-2025-10284Critical· 9.6
1y ago

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.

BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.

▾ MidnightEPSS 0.71%via NVD
CVE-2025-10283Critical· 9.6
1y ago

BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

▾ MidnightEPSS 0.48%via NVD

Most-affected vendors

By CVEs published in the period.