Daily digest
Sunday 12 October 2025
A quiet day: only 21 new CVEs against a recent average of about 63. Of those, 1 high. One arrived with exploitation evidence or public exploit code already attached. hcltech was the most-affected vendor with 7.
New this day, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2025-61884High· 7.5CISA KEVPoCVulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …
CVE-2025-33096Medium· 6.5IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion.
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using uncontrolled recursion.
CVE-2025-11630Medium· 6.3A vulnerability was found in RainyGao DocSys up to 2.02.36
A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uploadDoc.do of the component File Upload. Performing manipulation of the argument path results in path traversal. The at…
CVE-2025-11629Medium· 6.3A vulnerability has been found in RainyGao DocSys up to 2.02.36
A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Manage/getUserList.do. Such manipulation leads to sql injection. It is possible to launch the attack remotely. The exploi…
CVE-2025-2140Medium· 5.7IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper verification of source data.
CVE-2025-11636Medium· 5.6A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036
A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036. This issue affects some unknown processing of the component Account Handler. Such manipulation leads to server-side request forgery. The attack can be e…
CVE-2025-11631Medium· 5.4A vulnerability was determined in RainyGao DocSys up to 2.02.36
A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of the argument path can lead to path traversal. The attack…
CVE-2025-52616Medium· 5.3HCL Unica 12.1.10 can expose sensitive system information
HCL Unica 12.1.10 can expose sensitive system information. An attacker could use this information to form an attack plan by leveraging known vulnerabilities in the application.
CVE-2025-11628Medium· 4.7A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64
A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This affects an unknown function of the file /delete.php of the component Product Inventory Handler. This manipulation of t…
CVE-2025-31992Medium· 4.6HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters that are processed client-side in the context of the user's session.
CVE-2025-11637Medium· 4.3A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036
A vulnerability was detected in Tomofun Furbo 360 up to FB0035_FW_036. Impacted is an unknown function of the component Audio Handler. Performing manipulation results in race condition. The attack is possible to be carried out remotely. …
CVE-2025-11635Medium· 4.3A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036
A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036. This vulnerability affects unknown code of the component File Upload. This manipulation causes resource consumption. Remote exploitation of the attack is possible. …
Most-affected vendors
By CVEs published in the period.