Daily digest
Thursday 27 November 2025
A quiet day: only 3 new CVEs against a recent average of about 7. Severity skewed high: 1 critical and 1 high, 67% of the total. One arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 3 that matter most of the 3 published.
CVE-2025-12758High· 7.5PoCVersions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…
CVE-2025-34351CriticalRay's New Token Authentication is Disabled By Default
Ray's New Token Authentication is Disabled By Default
CVE-2025-13762NoneImproper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: befor…
Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial of Service when trying to starting new SWS sessions.This issue affects CyberArk Secure Web Sessions Extension: befor…
Most-affected vendors
By CVEs published in the period.