Daily digest
Friday 28 November 2025
6 new CVEs this day, in line with the recent average. Of those, 1 high. huawei was the most-affected vendor with 3.
New this day, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2025-58316High· 7.3DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.
DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-64313Medium· 5.3Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.
Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-66371Medium· 5.0Peppol-py is vulnerable to XXE attacks due to Saxon configuration
Peppol-py is vulnerable to XXE attacks due to Saxon configuration
CVE-2025-58312Medium· 5.1Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-13737Medium· 4.3The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21
The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This …
CVE-2025-66372Low· 2.8Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
Mustang before 2.16.3 allows exfiltrating files via XXE attacks.
Most-affected vendors
By CVEs published in the period.