VulnSea

Daily digest

Wednesday 29 October 2025

A busier-than-usual day with 21 new CVEs (recent average about 15). Of those, 4 high. One arrived with exploitation evidence or public exploit code already attached.

21
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2025-11201High· 8.10dayPoC
11mo ago

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

▾ Abyssalmlflow · mlflowEPSS 26%via OSV
CVE-2025-11200High· 8.10day
11mo ago

MLflow Weak Password Requirements Authentication Bypass Vulnerability

MLflow Weak Password Requirements Authentication Bypass Vulnerability

▾ Abyssalmlflow · mlflowEPSS 1.4%via OSV
CVE-2025-11232High· 7.5
11mo ago

To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qual…

To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char-replacement" must be empty (the default); and "ddns-qual…

▾ TwilightEPSS 0.42%via NVD
CVE-2025-64104High· 7.3
11mo ago

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

▾ Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.19%via OSV
CVE-2025-9544Medium· 6.5
11mo ago

The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capabilities or using a nonce

The Doppler Forms WordPress plugin through 2.5.1 registers an AJAX action install_extension without verifying user capabilities or using a nonce. As a result, any authenticated user — including those with the Subscriber role — can instal…

▾ SunlitEPSS 0.22%via NVD
CVE-2025-54384Medium· 6.3
11mo ago

CKAN vulnerable to stored XSS in resource description

CKAN vulnerable to stored XSS in resource description

▾ Sunlitckan · ckanEPSS 0.23%via OSV
CVE-2025-64100Medium· 6.1
11mo ago

CKAN vulnerable to fixed session IDs

CKAN vulnerable to fixed session IDs

▾ Sunlitckan · ckanEPSS 0.30%via OSV
CVE-2025-64289Medium· 5.9
11mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for W…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Premmerce Premmerce Product Search for WooCommerce premmerce-search allows Stored XSS.This issue affects Premmerce Product Search for W…

▾ SunlitPremmerce · premmerce-searchEPSS 0.18%via NVD
CVE-2025-54549Medium· 5.9
11mo ago

Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

Cryptographic validation of upgrade images could be circumventing by dropping a specifically crafted file into the upgrade ISO

▾ SunlitEPSS 0.09%via NVD
CVE-2025-58711Medium· 5.3
11mo ago

Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8.

Missing Authorization vulnerability in solwin Blog Designer PRO blog-designer-pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Blog Designer PRO: from n/a through <= 3.4.8.

▾ SunlitEPSS 0.27%via NVD
CVE-2025-58185Medium· 5.3
11mo ago

Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.

▾ Sunlitgolang · goEPSS 0.56%via NVD
CVE-2025-47912Medium· 5.3
11mo ago

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL

The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host component, enclosed within square brackets. …

▾ Sunlitgolang · goEPSS 0.47%via NVD

Most-affected vendors

By CVEs published in the period.