VulnSea

Daily digest

Friday 24 October 2025

10 new CVEs this day, in line with the recent average. Of those, 2 critical and 1 high.

10
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2025-43995Critical· 9.8
11mo ago

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability

Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mecha…

▾ Midnightdell · storage_managerEPSS 0.84%via NVD
CVE-2025-11253Critical· 9.8
11mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aksis Technology Inc

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aksis Technology Inc. Netty ERP allows SQL Injection. This issue affects Netty ERP: before V.1.1000.

▾ MidnightEPSS 0.44%via NVD
CVE-2025-62868High· 8.1
11mo ago

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This issue affects Edge CPT: from n/a through 1.4.

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Edge CPT allows PHP Local File Inclusion.This issue affects Edge CPT: from n/a through 1.4.

▾ TwilightEPSS 0.47%via NVD
CVE-2025-60419Medium· 6.2
11mo ago

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.

▾ SunlitEPSS 0.13%via NVD
CVE-2025-11576Medium· 4.3
11mo ago

The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5

The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 1.6.5. This is due to insufficient sanitization in the 'newcodebyte_cha…

▾ SunlitEPSS 0.29%via NVD
CVE-2025-11257Medium· 4.3
11mo ago

The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_save_blogs' AJAX endpoint in all versions up to, and including, 1.0.1

The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_save_blogs' AJAX endpoint in all versions up to, and including, 1.0.1. This makes it po…

▾ SunlitEPSS 0.20%via NVD
CVE-2025-62711Low· 3.1
11mo ago

Wasmtime is a runtime for WebAssembly

Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model related host-to-wasm trampolines in Wasmtime contained a bug where it's possible to carefully craft a component, which…

▾ Sunlitbytecodealliance · wasmtimeEPSS 0.43%via NVD
CVE-2025-4106None
11mo ago

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover dia…

An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable a diagnostic debug shell by uploading a platform and version-specific diagnostic package and executing a leftover dia…

▾ SunlitEPSS 0.32%via NVD
CVE-2025-40022None
11mo ago

crypto: af_alg - Fix incorrect boolean values in af_alg_ctx

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af_alg_ctx Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg") changed some fields f…

▾ SunlitLinux · LinuxEPSS 0.23%via CVEORG
CVE-2025-34502None
11mo ago

Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules

Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. Without cryptographic boot verification, an attacker with physical access can modify or replace the bootloader, kerne…

▾ SunlitEPSS 0.22%via NVD

Most-affected vendors

By CVEs published in the period.