VulnSea

Daily digest

Thursday 30 October 2025

A heavy day: 36 new CVEs, well above the recent average of about 16. Of those, 4 critical and 13 high. One arrived with exploitation evidence or public exploit code already attached. nagios was the most-affected vendor with 21.

36
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 36 published.

CVE-2024-14003Critical· 9.8
11mo ago

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach c…

▾ Midnightnagios · nagios_xiEPSS 2.3%via NVD
CVE-2024-13999Critical· 9.8⚖ disputed
11mo ago

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user

Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authen…

▾ Midnightnagios · nagios_xiEPSS 1.9%via NVD
CVE-2024-13996Critical· 9.8
11mo ago

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained…

▾ Midnightnagios · nagios_xiEPSS 1.1%via NVD
CVE-2024-13994Critical· 9.8
11mo ago

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper autho…

Nagios XI versions prior to 2024R1.1.2 contain a missing authorization control when the 'Allow Insecure Logins' option is enabled. Under this configuration, any user can create valid login credentials for other users without proper autho…

▾ Midnightnagios · nagios_xiEPSS 0.92%via NVD
CVE-2025-34284High· 8.8
11mo ago

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin

Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin. Insufficient validation of user-supplied parameters allows an authenticated administrator to inject shell metacharacters that are incorpora…

▾ Twilightnagios · nagios_xiEPSS 4.0%via NVD
CVE-2024-14005High· 8.8
11mo ago

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard

Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authenticated administrator to inject shell metacharacters that a…

▾ Twilightnagios · nagios_xiEPSS 4.0%via NVD
CVE-2024-14004High· 8.8
11mo ago

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf)

Nagios XI versions prior to 2024R1.2 contain a privilege escalation vulnerability related to NagVis configuration handling (nagvis.conf). An authenticated user could manipulate NagVis configuration data or leverage insufficiently validat…

▾ Twilightnagios · nagios_xiEPSS 1.1%via NVD
CVE-2024-13995High· 8.8
11mo ago

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data

Nagios XI versions prior to 2024R1.1.2 may (confirmed in 2024R1.1 and 2024R1.1.1) disclose sensitive user account information (including API keys and hashed passwords) to authenticated users who should not have access to that data. Expos…

▾ Twilightnagios · nagios_xiEPSS 1.3%via NVD
CVE-2025-11627Medium· 6.5PoC
11mo ago

The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log file poisoning in all versions up to, and including, 1.47

The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log file poisoning in all versions up to, and including, 1.47. This makes it possible for unauthenticated attackers to in…

▾ TwilightEPSS 0.34%via NVD
CVE-2025-64112High· 8.0
11mo ago

Statmatic is a Laravel and Git powered content management system (CMS)

Statmatic is a Laravel and Git powered content management system (CMS). Stored XSS vulnerabilities in Collections and Taxonomies allow authenticated users with content creation permissions to inject malicious JavaScript that executes whe…

▾ TwilightEPSS 0.30%via NVD
CVE-2025-46423High· 7.8
11mo ago

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vuln…

▾ Twilightdell · unity_operating_environmentEPSS 0.50%via NVD
CVE-2025-40105High· 7.8
11mo ago

vfs: Don't leak disconnected dentries on umount

In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount When user calls open_by_handle_at() on some inode that is not cached, we will create disconnected dentry for it. If suc…

▾ TwilightLinux · LinuxEPSS 0.16%via CVEORG

Most-affected vendors

By CVEs published in the period.