VulnSea

Daily digest

Thursday 23 October 2025

A quiet day: only 6 new CVEs against a recent average of about 12. Of those, 1 high.

6
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2025-12105High· 7.5
11mo ago

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an …

▾ TwilightEPSS 0.46%via NVD
CVE-2025-41073Medium· 6.5
11mo ago

Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total

Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated attacker to download a ZIP file containing files from the server, including those located in parent directories (e.g., ..…

▾ Sunlittesigandia · gandia_integra_totalEPSS 0.38%via NVD
CVE-2025-7730Medium· 6.4
11mo ago

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter in all versions up to, and including, 5.4.5 due to insufficient input sanitization and output escaping. This makes it …

▾ SunlitEPSS 0.23%via NVD
CVE-2025-57848Medium· 6.4
11mo ago

A container privilege escalation flaw was found in certain Container-native Virtualization images

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an atta…

▾ SunlitEPSS 0.19%via NVD
CVE-2025-11128Medium· 5.0
11mo ago

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds…

The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5.1.0 via the 'feedzy_sanitize_feeds…

▾ SunlitEPSS 0.29%via NVD
CVE-2025-10355None
11mo ago

Open redirection vulnerability in MOLGENIS EMX2 v11.14.0

Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious URL using a manipulated redirection parameter, potentially leading users to phishing sites or other malicious destinati…

▾ SunlitEPSS 0.30%via NVD

Most-affected vendors

By CVEs published in the period.