VulnSea

Daily digest

Wednesday 22 October 2025

A heavy day: 37 new CVEs, well above the recent average of about 10. Severity skewed high: 10 critical and 13 high, 62% of the total. 3 arrived with exploitation evidence or public exploit code already attached.

37
New CVEs
10
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 37 published.

CVE-2024-58274High· 8.3⚠ Exploited
11mo ago

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

▾ MidnightEPSS 19%via NVD
CVE-2025-62023Critical· 9.0PoC
11mo ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.

Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through 250905.

▾ AbyssalCristián Lávaque · s2memberEPSS 0.42%via NVD
CVE-2025-60206Critical· 10.0
11mo ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through <= 7.8.3.

Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through <= 7.8.3.

▾ MidnightEPSS 0.53%via NVD
CVE-2025-57870Critical· 10.0
11mo ago

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes

A SQL Injection vulnerability exists in Esri ArcGIS Server versions 11.3, 11.4 and 11.5 on Windows, Linux and Kubernetes. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary SQL commands via a specific ArcGI…

▾ Midnightesri · arcgis_serverEPSS 0.54%via NVD
CVE-2025-49060Critical· 10.0
11mo ago

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue affects Wastia: from n/a through < 1.1.3.

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell to a Web Server.This issue affects Wastia: from n/a through < 1.1.3.

▾ MidnightEPSS 0.46%via NVD
CVE-2025-48106Critical· 10.0
11mo ago

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clanora: from n/a through < 1.3.1.

Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious Files.This issue affects Clanora: from n/a through < 1.3.1.

▾ MidnightEPSS 0.62%via NVD
CVE-2025-60214Critical· 9.8
11mo ago

Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/a through < 1.3.0.

Deserialization of Untrusted Data vulnerability in BoldThemes Goldenblatt goldenblatt allows Object Injection.This issue affects Goldenblatt: from n/a through < 1.3.0.

▾ MidnightEPSS 0.59%via NVD
CVE-2025-60039Critical· 9.8
11mo ago

Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0.

Deserialization of Untrusted Data vulnerability in rascals Noisa noisa allows Object Injection.This issue affects Noisa: from n/a through <= 2.6.0.

▾ MidnightEPSS 0.56%via NVD
CVE-2025-59007Critical· 9.8
11mo ago

Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.This issue affects TF Woo Product Grid Addon For Elementor: from n/a through <= 1.0.1.

Deserialization of Untrusted Data vulnerability in themesflat TF Woo Product Grid Addon For Elementor tf-woo-product-grid allows Object Injection.This issue affects TF Woo Product Grid Addon For Elementor: from n/a through <= 1.0.1.

▾ MidnightEPSS 0.49%via NVD
CVE-2025-56447Critical· 9.8
11mo ago

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

▾ MidnightEPSS 0.29%via NVD
CVE-2025-59557Critical· 9.3
11mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQL Injection.This issue affects Learts Addons: from n/a through < 1.7.5.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQL Injection.This issue affects Learts Addons: from n/a through < 1.7.5.

▾ MidnightEPSS 0.37%via NVD
CVE-2025-52740High· 8.8
11mo ago

Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows Object Injection.This issue affects Boldermail: from n/a through <= 2.4.0.

Deserialization of Untrusted Data vulnerability in Hernan Villanueva Boldermail boldermail allows Object Injection.This issue affects Boldermail: from n/a through <= 2.4.0.

▾ TwilightEPSS 0.53%via NVD

Most-affected vendors

By CVEs published in the period.