VulnSea

Daily digest

Thursday 13 November 2025

10 new CVEs this day, in line with the recent average. Severity skewed high: 6 high, 60% of the total. One arrived with exploitation evidence or public exploit code already attached.

10
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2025-60689Medium· 5.4PoC
10mo ago

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl…

▾ Twilightlinksys · e1200_firmwareEPSS 18%via NVD
CVE-2025-12967High· 8.0
10mo ago

AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance

AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance

▾ Twilightaws-advanced-python-wrapper · aws-advanced-python-wrapperEPSS 0.73%via OSV
CVE-2025-64509High· 7.5
10mo ago

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)

▾ Twilightbugsink · bugsinkEPSS 0.32%via OSV
CVE-2025-64508High· 7.5
10mo ago

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input

▾ Twilightbugsink · bugsinkEPSS 0.47%via OSV
CVE-2025-47913High· 7.5
10mo ago

golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS (CVE-2025-47913)

A flaw in golang.org/x/crypto/ssh/agent causes the SSH agent client to panic when a peer responds with the generic SSH_AGENT_SUCCESS (0x06) message to requests expecting typed replies (e.g., List, Sign). The unmarshal layer produces an une…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.6)EPSS 0.62%via CSAF
CVE-2025-12765High· 7.5
10mo ago

pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.

pgAdmin <= 9.9  is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate verification.

▾ Twilightpgadmin · pgadmin_4EPSS 0.22%via NVD
CVE-2025-12764High· 7.5
10mo ago

pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amo…

pgAdmin <= 9.9  is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker to inject special LDAP characters in the username, causing the DC/LDAP server and the client to process an unusual amo…

▾ Twilightpgadmin · pgadmin_4EPSS 0.45%via NVD
CVE-2025-12763Medium· 6.8
10mo ago

pgAdmin 4 has command injection vulnerability on Windows systems

pgAdmin 4 has command injection vulnerability on Windows systems

▾ Sunlitpgadmin4 · pgadmin4EPSS 0.94%via OSV
CVE-2025-64292Medium· 6.5
10mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PascalBajorat Analytics Germanized for Google Analytics ga-germanized allows DOM-Based XSS.This issue affects Analytics Germanized for …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PascalBajorat Analytics Germanized for Google Analytics ga-germanized allows DOM-Based XSS.This issue affects Analytics Germanized for …

▾ SunlitEPSS 0.15%via NVD
CVE-2025-8397Medium· 6.4
10mo ago

The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbutton shortcode in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping …

The Save as PDF Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's restpackpdfbutton shortcode in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping …

▾ SunlitEPSS 0.23%via NVD

Most-affected vendors

By CVEs published in the period.