VulnSea

Daily digest

Friday 28 November 2025

6 new CVEs this day, in line with the recent average. Of those, 1 high. huawei was the most-affected vendor with 3.

6
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2025-58316High· 7.3
10mo ago

DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may affect availability.

▾ Twilighthuawei · harmonyosEPSS 0.07%via NVD
CVE-2025-64313Medium· 5.3
10mo ago

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may affect availability.

▾ Sunlithuawei · harmonyosEPSS 0.07%via NVD
CVE-2025-66371Medium· 5.0
10mo ago

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

Peppol-py is vulnerable to XXE attacks due to Saxon configuration

▾ Sunlitpeppol-py · peppol-pyEPSS 0.32%via OSV
CVE-2025-58312Medium· 5.1
10mo ago

Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affect availability.

▾ Sunlithuawei · harmonyosEPSS 0.08%via NVD
CVE-2025-13737Medium· 4.3
10mo ago

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21

The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.21. This is due to missing or incorrect nonce validation on the 'unlinkUser' function. This …

▾ SunlitEPSS 0.15%via NVD
CVE-2025-66372Low· 2.8
10mo ago

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

Mustang before 2.16.3 allows exfiltrating files via XXE attacks.

▾ SunlitEPSS 0.12%via NVD

Most-affected vendors

By CVEs published in the period.