VulnSea

Daily digest

Tuesday 11 November 2025

14 new CVEs this day, in line with the recent average. Of those, 6 high. 3 arrived with exploitation evidence or public exploit code already attached.

14
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 14 published.

CVE-2025-9223High· 8.8PoC
10mo ago

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection vulnerability due to the improper configuration in the execute program action feature.

▾ MidnightEPSS 4.2%via NVD
CVE-2024-32011High· 8.8
10mo ago

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and al…

▾ TwilightEPSS 0.39%via NVD
CVE-2025-30398High· 8.1
10mo ago

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

▾ Twilightmicrosoft · nuance_powerscribe_360EPSS 0.79%via NVD
CVE-2024-32010High· 7.8
10mo ago

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to extraction of database credentials via a world-readable credential file. This allows an attacker to c…

▾ TwilightEPSS 0.12%via NVD
CVE-2024-32009High· 7.8
10mo ago

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to wrongly set permissions to a binary which allows any local attack…

▾ TwilightEPSS 0.11%via NVD
CVE-2024-32008High· 7.8
10mo ago

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2)

A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to a local privilege escalation due to an exposed debug interface on the localhost. This allows any loca…

▾ TwilightEPSS 0.12%via NVD
CVE-2025-12748Medium· 5.5PoC
10mo ago

A flaw was discovered in libvirt in the XML file processing

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a…

▾ TwilightEPSS 0.21%via NVD
CVE-2025-11988Medium· 5.3PoC
10mo ago

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22

The Crypto plugin for WordPress is vulnerable to unauthorized manipulation of data in all versions up to, and including, 2.22. This is due to the plugin registering an unauthenticated AJAX action (wp_ajax_nopriv_crypto_connect_ajax_proce…

▾ TwilightEPSS 0.34%via NVD
CVE-2025-12671Medium· 6.4
10mo ago

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping…

The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_iconics' shortcode in all versions up to, and including, 0.0.4 due to insufficient input sanitization and output escaping…

▾ SunlitEPSS 0.22%via NVD
CVE-2025-12668Medium· 6.4
10mo ago

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization an…

The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_countdown_timer' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization an…

▾ SunlitEPSS 0.22%via NVD
CVE-2025-11999Medium· 5.3
10mo ago

The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and includi…

The Add Multiple Marker plugin for WordPress is vulnerable to unauthorized modification of data to due to a missing capability check on the addmultiplemarker_reset_map() and amm_save_map_api() functions in all versions up to, and includi…

▾ SunlitEPSS 0.27%via NVD
CVE-2025-11891Medium· 5.3
10mo ago

The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files

The Shelf Planner plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potential…

▾ SunlitEPSS 0.31%via NVD

Most-affected vendors

By CVEs published in the period.