Daily digest
Monday 24 November 2025
A busier-than-usual day with 9 new CVEs (recent average about 7). Of those, 3 high. One arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 9 that matter most of the 9 published.
CVE-2024-14015High· 7.1PoCThe WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users s…
The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users s…
CVE-2025-13609High· 8.2A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID)
A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This acti…
CVE-2025-64761HighOpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
CVE-2025-63674Medium· 6.8An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.
An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.
CVE-2025-36150Medium· 5.9IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.
CVE-2025-29933Medium· 5.5Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service
Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service
CVE-2025-66019Mediumpypdf's LZWDecode streams be manipulated to exhaust RAM
pypdf's LZWDecode streams be manipulated to exhaust RAM
CVE-2025-12569Medium· 4.7The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue
CVE-2024-14007NoneShenzhen TVT Digital Technology Co., Ltd
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 control protocol. By sending a single crafted TCP pa…
Most-affected vendors
By CVEs published in the period.