VulnSea

Daily digest

Tuesday 14 October 2025

A heavy day: 159 new CVEs, well above the recent average of about 71. Severity skewed high: 12 critical and 72 high, 53% of the total. 4 arrived with exploitation evidence or public exploit code already attached. adobe was the most-affected vendor with 29.

159
New CVEs
12
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 159 published.

CVE-2025-34267Critical· 9.9PoC
12mo ago

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) w…

Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) w…

▾ Abyssalflowiseai · flowiseEPSS 6.6%via NVD
CVE-2025-9063Critical· 9.8
12mo ago

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the …

▾ Midnightrockwellautomation · factorytalk_viewEPSS 0.39%via NVD
CVE-2025-7328Critical· 9.8
12mo ago

Multiple Broken Authentication security issues exist in the affected product

Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, …

▾ Midnightrockwellautomation · 1783-natr_firmwareEPSS 0.54%via NVD
CVE-2025-5946High· 7.2PoC
12mo ago

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. On the poller parameter…

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra Monitoring (Poller reload setup in the configuration modules) allows OS Command Injection. On the poller parameter…

▾ Midnightcentreon · centreon_webEPSS 14%via NVD
CVE-2025-46581Critical· 9.8
12mo ago

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability

ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

▾ MidnightEPSS 0.80%via NVD
CVE-2025-42937Critical· 9.8
12mo ago

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users

SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated attacker could traverse to the parent directory and over-write system files causing high impact on confidentiality i…

▾ MidnightEPSS 0.74%via NVD
CVE-2025-40765Critical· 9.8
12mo ago

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3)

A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to…

▾ Midnightsiemens · telecontrol_server_basicEPSS 0.53%via NVD
CVE-2025-10610Critical· 9.8
12mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Information Processing Industry and Foreign Trade Inc. Winsure allows Blind SQL Injection. This issue affects Winsure: …

▾ MidnightEPSS 0.37%via NVD
CVE-2025-49553Critical· 9.3
12mo ago

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser

Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires u…

▾ Midnightadobe · connectEPSS 0.53%via NVD
CVE-2025-9064Critical· 9.1
12mo ago

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerabilit…

▾ Midnightrockwellautomation · factorytalk_viewEPSS 0.61%via NVD
CVE-2025-54603Critical· 9.0
12mo ago

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.

▾ MidnightEPSS 0.75%via NVD
CVE-2025-42910Critical· 9.0
12mo ago

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files

Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attacker to upload arbitrary files. These files could include executables which might be downloaded and executed by the use…

▾ MidnightEPSS 0.48%via NVD

Most-affected vendors

By CVEs published in the period.