VulnSea

Daily digest

Thursday 16 October 2025

A quiet day: only 35 new CVEs against a recent average of about 94. Of those, 6 critical and 7 high. hcltech was the most-affected vendor with 5.

35
New CVEs
6
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 35 published.

CVE-2025-62583Critical· 9.8
11mo ago

Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

▾ Midnightnavercorp · whaleEPSS 0.50%via NVD
CVE-2025-55089Critical· 9.8
11mo ago

In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver

In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver. It could cause a remote execurtion after receiving a crafted sequence of packets

▾ Midnighteclipse · threadx_filexEPSS 0.51%via NVD
CVE-2025-41018Critical· 9.8
11mo ago

SQL injection in Sergestec's Exito v8.0

SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'cat' parameter in '/public.php'.

▾ Midnightsergestec · exitoEPSS 0.46%via NVD
CVE-2025-10850Critical· 9.8
11mo ago

The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4

The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1.4. This is due to the hardcoded password in the 'fb_ajax_login_or_register' function and in the 'google_ajax_login_or…

▾ MidnightEPSS 0.61%via NVD
CVE-2025-10742Critical· 9.8
11mo ago

The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6

The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.8.6. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization …

▾ MidnightEPSS 0.54%via NVD
CVE-2025-9804Critical· 9.6
11mo ago

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs

An improper access control vulnerability exists in multiple WSO2 products due to insufficient permission enforcement in certain internal SOAP Admin Services and System REST APIs. A low-privileged user may exploit this flaw to perform una…

▾ Midnightwso2 · api_control_planeEPSS 0.56%via NVD
CVE-2025-10706High· 8.8
11mo ago

The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_plugin_cb' function in all versions up to, and including, 1.0.14

The Classified Pro theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check in the 'cwp_addons_update_plugin_cb' function in all versions up to, and including, 1.0.14. This makes it possible…

▾ TwilightEPSS 0.64%via NVD
CVE-2025-62580High· 7.8
11mo ago

ASDA-Soft Stack-based Buffer Overflow Vulnerability

ASDA-Soft Stack-based Buffer Overflow Vulnerability

▾ Twilightdeltaww · asda_softEPSS 0.20%via NVD
CVE-2025-62579High· 7.8
11mo ago

ASDA-Soft Stack-based Buffer Overflow Vulnerability

ASDA-Soft Stack-based Buffer Overflow Vulnerability

▾ Twilightdeltaww · asda_softEPSS 0.20%via NVD
CVE-2025-62585High· 7.5
11mo ago

Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.

Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.

▾ Twilightnavercorp · whaleEPSS 0.37%via NVD
CVE-2025-62584High· 7.5
11mo ago

Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.

Whale browser before 4.33.325.17 allows an attacker to bypass the Same-Origin Policy in a dual-tab environment.

▾ Twilightnavercorp · whaleEPSS 0.21%via NVD
CVE-2025-41020High· 7.5
11mo ago

Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0

Insecure direct object reference (IDOR) vulnerability in Sergestec's Exito v8.0. This vulnerability allows an attacker to access data belonging to other customers through the 'id' parameter in '/admin/ticket_a4.php'.

▾ Twilightsergestec · exitoEPSS 0.34%via NVD

Most-affected vendors

By CVEs published in the period.