Daily digest
Thursday 13 November 2025
10 new CVEs this day, in line with the recent average. Severity skewed high: 6 high, 60% of the total. One arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 10 that matter most of the 10 published.
CVE-2025-60689Medium· 5.4PoCAn unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)
An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl…
CVE-2025-12967High· 8.0AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance
CVE-2025-64509High· 7.5Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)
CVE-2025-64508High· 7.5Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input
CVE-2025-47913High· 7.5golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)
A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an une…
CVE-2025-12765High· 7.5pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.
pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.
CVE-2025-12764High· 7.5pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amo…
pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amo…
CVE-2025-12763Medium· 6.8pgAdmin 4 has command injection vulnerability on Windows systems
pgAdmin 4 has command injection vulnerability on Windows systems
CVE-2025-64292Medium· 6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PascalBajorat Analytics Germanized for Google Analytics ga-germanized allows DOM-Based XSS.This issue affects Analytics Germanized for …
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PascalBajorat Analytics Germanized for Google Analytics ga-germanized allows DOM-Based XSS.This issue affects Analytics Germanized for …
CVE-2025-8397Medium· 6.4The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbutton shortcode in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping …
The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbutton shortcode in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping …
Most-affected vendors
By CVEs published in the period.