VulnSea

Daily digest

Monday 27 October 2025

A heavy day: 26 new CVEs, well above the recent average of about 10. Of those, 5 high. tenda was the most-affected vendor with 3.

26
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 26 published.

CVE-2025-12234High· 8.8
11mo ago

A vulnerability has been found in Tenda CH22 1.0.0.1

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function fromSafeMacFilter of the file /goform/SafeMacFilter. The manipulation of the argument page leads to buffer overflow. The attack may be initiated remotely. Th…

▾ Twilighttenda · ch22_firmwareEPSS 1.1%via NVD
CVE-2025-12232High· 8.8
11mo ago

A vulnerability was detected in Tenda CH22 1.0.0.1

A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter of the file /goform/SafeClientFilter. Performing a manipulation of the argument page results in buffer overflow. The …

▾ Twilighttenda · ch22_firmwareEPSS 4.9%via NVD
CVE-2025-12210High· 8.8
11mo ago

A vulnerability was identified in Tenda O3 1.0.0.10(2478)

A vulnerability was identified in Tenda O3 1.0.0.10(2478). Affected by this vulnerability is the function SetValue/GetValue of the file /goform/AdvSetLanip. The manipulation of the argument lanIp leads to stack-based buffer overflow. It …

▾ Twilighttenda · o3_firmware1.0.0.10(2478)EPSS 1.1%via NVD
CVE-2025-61385High
11mo ago

pg8000 SQL injection vulnerability via a specially crafted Python list input

pg8000 SQL injection vulnerability via a specially crafted Python list input

▾ Twilightpg8000 · pg8000EPSS 0.36%via OSV
CVE-2025-12253High· 7.3
11mo ago

A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0

A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/portal/get_expiredtime.php. This manipulation of the argument uid causes sql inject…

▾ Twilightamttgroup · hibosEPSS 0.44%via NVD
CVE-2025-62987Medium· 6.5
11mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordP…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builderall Builder for WordPress builderall-cheetah-for-wp allows Stored XSS.This issue affects Builderall Builder for WordP…

▾ SunlitEPSS 0.17%via NVD
CVE-2025-62967Medium· 6.5
11mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento DirectoryPress directorypress allows DOM-Based XSS.This issue affects DirectoryPress: from n/a through <= 3.6.25.

▾ SunlitEPSS 0.17%via NVD
CVE-2025-62951Medium· 6.5
11mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icc0rz H5P h5p allows Stored XSS.This issue affects H5P: from n/a through <= 1.16.0.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in icc0rz H5P h5p allows Stored XSS.This issue affects H5P: from n/a through <= 1.16.0.

▾ SunlitEPSS 0.20%via NVD
CVE-2025-62937Medium· 6.5
11mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johnny Post List Featured Image post-list-featured-image allows Stored XSS.This issue affects Post List Featured Image: from n/a throug…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Johnny Post List Featured Image post-list-featured-image allows Stored XSS.This issue affects Post List Featured Image: from n/a throug…

▾ SunlitEPSS 0.20%via NVD
CVE-2025-62907Medium· 6.5
11mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attach…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in aviplugins.com Custom Post Type Attachment custom-post-type-pdf-attachment allows Stored XSS.This issue affects Custom Post Type Attach…

▾ SunlitEPSS 0.20%via NVD
CVE-2025-12328Medium· 6.3
11mo ago

A vulnerability was identified in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5

A vulnerability was identified in shawon100 RUET OJ up to 18fa45b0a669fa1098a0b8fc629cf6856369d9a5. Impacted is an unknown function of the file /contestproblem.php. Such manipulation of the argument Name leads to sql injection. The attac…

▾ Sunlitshawonruet · ruet_ojEPSS 0.27%via NVD
CVE-2025-12261Medium· 6.3
11mo ago

A vulnerability was found in CodeAstro Gym Management System 1.0

A vulnerability was found in CodeAstro Gym Management System 1.0. This affects an unknown function of the file /admin/actions/remove-announcement.php. Performing a manipulation of the argument ID results in sql injection. The attack can …

▾ Sunlitcodeastro · gym_management_systemEPSS 0.45%via NVD

Most-affected vendors

By CVEs published in the period.