VulnSea

Daily digest

Wednesday 19 November 2025

A quiet day: only 3 new CVEs against a recent average of about 10. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

3
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 3 that matter most of the 3 published.

CVE-2025-64521Medium· 4.8
10mo ago

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_se…

authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client_id and client_secret to an OAuth provider, authentik creates a service account for the provider. In previous authent…

▾ Sunlitauthentik-client · authentik-clientEPSS 0.22%via OSV
CVE-2025-34337None
10mo ago

eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption ora…

eGovFramework/egovframe-common-components versions up to and including 4.3.1 includes Web Editor image upload and related file delivery functionality that uses symmetric encryption to protect URL parameters, but exposes an encryption ora…

▾ SunlitEPSS 0.27%via NVD
CVE-2025-34336None
10mo ago

eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints

eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vulnerability via the /utl/wed/insertImage.do and /utl/wed/insertImageCk.do image upload endpoints. These controllers acc…

▾ SunlitEPSS 0.56%via NVD

Most-affected vendors

By CVEs published in the period.