Daily digest
Tuesday 11 November 2025
14 new CVEs this day, in line with the recent average. Of those, 6 high. 3 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 14 published.
CVE-2025-9223High· 8.8PoCZohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.
CVE-2024-32011High· 8.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and al…
CVE-2025-30398High· 8.1Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.
CVE-2024-32010High· 7.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to c…
CVE-2024-32009High· 7.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to wrongly set permissions to a binary which allows any local attack…
CVE-2024-32008High· 7.8A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)
A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any loca…
CVE-2025-12748Medium· 5.5PoCA flaw was discovered in libvirt in the XML file processing
A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a…
CVE-2025-11988Medium· 5.3PoCThe Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22
The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_proce…
CVE-2025-12671Medium· 6.4The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping…
The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping…
CVE-2025-12668Medium· 6.4The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization an…
The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization an…
CVE-2025-11999Medium· 5.3The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and includi…
The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and includi…
CVE-2025-11891Medium· 5.3The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files
The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potential…
Most-affected vendors
By CVEs published in the period.