VulnSea

Daily digest

Monday 13 October 2025

A busier-than-usual day with 74 new CVEs (recent average about 63). Of those, 4 critical and 28 high. 3 arrived with exploitation evidence or public exploit code already attached. ivanti was the most-affected vendor with 13.

74
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 74 published.

CVE-2025-39964High· 7.8CISA KEVPoC
12mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

▾ Abyssallinux · linux_kernelEPSS 1.3%via NVD
CVE-2025-62360High· 8.8PoC
12mo ago

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the i…

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the i…

▾ Midnightwegia · wegiaEPSS 0.89%via NVD
CVE-2025-6919Critical· 9.8
12mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License Tracking System allows SQL Injection. This issue affects …

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information Technology Software Development Technologies Aykome License Tracking System allows SQL Injection. This issue affects …

▾ MidnightEPSS 0.37%via NVD
CVE-2025-27258Critical· 9.8
12mo ago

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an escalation of privilege.

▾ Midnightericsson · network_managerEPSS 0.30%via NVD
CVE-2025-9713High· 8.8
12mo ago

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

▾ Twilightivanti · endpoint_managerEPSS 15%via NVD
CVE-2025-9976Critical· 9.0
12mo ago

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025x could allow an attacker to execute arbitrary code on the user's machine.

▾ MidnightEPSS 0.90%via NVD
CVE-2025-37729Critical· 9.1
12mo ago

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted strin…

Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise (ECE) can lead to a malicious actor with Admin access exfiltrating sensitive information and issuing commands via a specially crafted strin…

▾ Midnightelastic · elastic_cloud_enterpriseEPSS 0.66%via NVD
CVE-2025-62177High· 8.8
12mo ago

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar.php endpoint, specifically in the id_…

▾ Twilightwegia · wegiaEPSS 0.53%via NVD
CVE-2025-11653High· 8.8
12mo ago

A vulnerability was determined in UTT HiPER 2620G up to 3.1.4

A vulnerability was determined in UTT HiPER 2620G up to 3.1.4. Impacted is the function strcpy of the file /goform/fNTP. This manipulation of the argument NTPServerIP causes buffer overflow. It is possible to initiate the attack remotely…

▾ Twilightutt · 2620g_firmwareEPSS 0.75%via NVD
CVE-2025-11652High· 8.8
12mo ago

A vulnerability was found in UTT 进取 518G up to V3v3.2.7-210919-161313

A vulnerability was found in UTT 进取 518G up to V3v3.2.7-210919-161313. This issue affects some unknown processing of the file /goform/formTaskEdit_ap. The manipulation of the argument txtMin2 results in buffer overflow. The attack may be…

▾ Twilightutt · 518g_firmwareEPSS 0.84%via NVD
CVE-2025-11651High· 8.8
12mo ago

A vulnerability has been found in UTT 进取 518G up to V3v3.2.7-210919-161313

A vulnerability has been found in UTT 进取 518G up to V3v3.2.7-210919-161313. This vulnerability affects the function sub_4247AC of the file /goform/formRemoteControl. The manipulation of the argument Profile leads to buffer overflow. The …

▾ Twilightutt · 518g_firmwareEPSS 0.84%via NVD
CVE-2025-62179High· 8.8
12mo ago

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/cadastro_funcionario_pessoa_existente.php endpoint, spe…

▾ Twilightwegia · wegiaEPSS 0.43%via NVD

Most-affected vendors

By CVEs published in the period.