VulnSea

Daily digest

Monday 24 November 2025

A busier-than-usual day with 9 new CVEs (recent average about 7). Of those, 3 high. One arrived with exploitation evidence or public exploit code already attached.

9
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 9 that matter most of the 9 published.

CVE-2024-14015High· 7.1PoC
10mo ago

The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users s…

The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users s…

▾ MidnightEPSS 0.40%via NVD
CVE-2025-13609High· 8.2
10mo ago

A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID)

A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This acti…

▾ TwilightEPSS 0.44%via NVD
CVE-2025-64761High
10mo ago

OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.36%via OSV
CVE-2025-63674Medium· 6.8
10mo ago

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding the bootloader on the SD card.

▾ Sunlitblurams · a31c_firmwareEPSS 0.29%via NVD
CVE-2025-36150Medium· 5.9
10mo ago

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

▾ Sunlitibm · concertEPSS 0.18%via NVD
CVE-2025-29933Medium· 5.5
10mo ago

Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service

Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a crash or denial of service

▾ Sunlitamd · uprofEPSS 0.11%via NVD
CVE-2025-66019Medium
10mo ago

pypdf's LZWDecode streams be manipulated to exhaust RAM

pypdf's LZWDecode streams be manipulated to exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.36%via OSV
CVE-2025-12569Medium· 4.7
10mo ago

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before redirecting the user to its value, leading to an Open Redirect issue

▾ SunlitEPSS 0.20%via NVD
CVE-2024-14007None
10mo ago

Shenzhen TVT Digital Technology Co., Ltd

Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions prior to 1.3.4 contain an authentication bypass in the NVMS-9000 control protocol. By sending a single crafted TCP pa…

▾ SunlitEPSS 0.86%via NVD

Most-affected vendors

By CVEs published in the period.