VulnSea

Daily digest

Friday 10 October 2025

A heavy day: 89 new CVEs, well above the recent average of about 55. Of those, 1 critical and 28 high. 5 arrived with exploitation evidence or public exploit code already attached. samsung was the most-affected vendor with 24.

89
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 89 published.

CVE-2025-61929Critical· 9.6
12mo ago

Cherry Studio is a desktop client that supports for multiple LLM providers

Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation URL, it parses the base64-encoded configuration data and d…

▾ Midnightcherry-ai · cherry_studioEPSS 0.47%via NVD
CVE-2025-11586High· 8.8
12mo ago

A vulnerability was determined in Tenda AC7 15.03.06.44

A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgrade. This manipulation of the argument newVersion causes stack-based buffer overflow. The attack is possible to be ca…

▾ Twilighttenda · ac7_firmwareEPSS 0.87%via NVD
CVE-2025-8093High· 8.8
12mo ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authentication Bypass.This issue affects Authenticator Login: from 0.0.0 before 2.1.8.

▾ Twilightauthenticator_login_project · authenticator_loginEPSS 0.35%via NVD
CVE-2025-25018High· 8.7
12mo ago

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation in Kibana can lead to stored Cross-Site Scripting (XSS)

▾ Twilightelastic · kibanaEPSS 0.23%via NVD
CVE-2025-21065Medium· 6.6PoC
12mo ago

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

Improper input validation in Retail Mode prior to version 5.59.11 allows self attackers to execute privileged commands on their own devices.

▾ TwilightEPSS 0.19%via NVD
CVE-2025-21064High· 8.8
12mo ago

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

Improper authentication in Smart Switch prior to version 3.7.66.6 allows adjacent attackers to access transferring data.

▾ Twilightsamsung · smart_switchEPSS 0.27%via NVD
CVE-2025-48043High· 8.6
12mo ago

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2.

Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1.1 before 3.6.2.

▾ Twilightash-project · ashEPSS 0.39%via NVD
CVE-2025-52650High· 8.2
12mo ago

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

Inline script execution allowed in CSP vulnerability has been identified in HCL AION v2.0

▾ Twilighthcltech · aionEPSS 0.23%via NVD
CVE-2025-25017High· 8.2
12mo ago

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

Improper Neutralization of Input During Web Page Generation in Kibana can lead to Cross-Site Scripting (XSS)

▾ Twilightelastic · kibanaEPSS 0.27%via NVD
CVE-2025-61864High· 7.8
12mo ago

A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier

A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.

▾ Twilightfujielectric · monitouch_v-sftEPSS 0.17%via NVD
CVE-2025-61863High· 7.8
12mo ago

An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier

An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary…

▾ Twilightfujielectric · monitouch_v-sftEPSS 0.17%via NVD
CVE-2025-61862High· 7.8
12mo ago

An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier

An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary…

▾ Twilightfujielectric · monitouch_v-sftEPSS 0.17%via NVD

Most-affected vendors

By CVEs published in the period.