Daily digest
Sunday 19 October 2025
A quiet day: only 7 new CVEs against a recent average of about 66. Of those, 2 high.
New this day, ranked by depth score
The 7 that matter most of the 7 published.
CVE-2025-11943High· 7.3A vulnerability has been found in 70mai X200 up to 20251010
A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to use of default credentials. The attack can be initiated r…
CVE-2025-11942High· 7.3A flaw has been found in 70mai X200 up to 20251010
A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been p…
CVE-2025-11941Medium· 5.4A vulnerability was detected in e107 CMS up to 2.3.3
A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler. Performing manipulation of the argument multiaction[] resul…
CVE-2025-62672Medium· 5.3rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact
rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecified other impact. This occurs in memcpy in the RPLAY_DATA case in rplay_unpack in librplay/rplay.c, potentially reachab…
CVE-2025-11944Medium· 4.7A vulnerability was determined in givanz Vvveb up to 1.0.7.3
A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. This manipulation causes sql injection. The attack may be init…
CVE-2025-11946Low· 3.5A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1
A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp of the component Add Contact Page. Performing manipulation of the argument First Name/L…
CVE-2025-11945Low· 3.5A vulnerability was identified in toeverything AFFiNE up to 0.24.1
A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the component Avatar Upload Image Endpoint. Such manipulation leads to cross site scripting. The attack may be launched remote…
Most-affected vendors
By CVEs published in the period.