VulnSea

Daily digest

Thursday 20 November 2025

A heavy day: 16 new CVEs, well above the recent average of about 9. Of those, 4 high. revive-adserver was the most-affected vendor with 10.

16
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2025-62164High· 8.8
10mo ago

vLLM deserialization vulnerability leading to DoS and potential RCE

vLLM deserialization vulnerability leading to DoS and potential RCE

▾ Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2025-48986High· 8.8
10mo ago

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change other users' email address and potentialy take over their accounts using the forgot password functionality.

▾ Twilightrevive-adserver · revive_adserverEPSS 0.62%via NVD
CVE-2025-65106High
10mo ago

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

▾ Twilightlangchain-core · langchain-coreEPSS 0.51%via OSV
CVE-2025-25613High· 7.5
10mo ago

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing user…

▾ Twilightfs · s3150-8t2f_firmwareEPSS 0.23%via NVD
CVE-2025-62372Medium· 6.5
10mo ago

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs

▾ Sunlitvllm · vllmEPSS 0.38%via OSV
CVE-2025-55128Medium· 6.5
10mo ago

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”

HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in the “userlog-index.php”. An attacker with access to the admin interface could request an arbitrarily large number of it…

▾ Sunlitaquaplatform · revive_adserverEPSS 0.40%via NVD
CVE-2025-52670Medium· 6.5
10mo ago

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete banners owned by other accounts

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.32%via NVD
CVE-2025-55124Medium· 6.1
10mo ago

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.41%via NVD
CVE-2025-48987Medium· 6.1
10mo ago

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XSS attack.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.51%via NVD
CVE-2025-55123Medium· 5.4
10mo ago

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be able to craft XSS attacks to their own advertiser users.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.45%via NVD
CVE-2025-52668Medium· 5.4
10mo ago

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes potential information disclosure and session hijacking via a stored XSS attack.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.53%via NVD
CVE-2025-52667Medium· 5.4
10mo ago

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS attack to be possible for a logged in manager user.

▾ Sunlitrevive-adserver · revive_adserverEPSS 0.37%via NVD

Most-affected vendors

By CVEs published in the period.