Daily digest
Monday 1 December 2025
A heavy day: 64 new CVEs, well above the recent average of about 6. Severity skewed high: 3 critical and 31 high, 53% of the total. 6 arrived with exploitation evidence or public exploit code already attached. getgrav was the most-affected vendor with 15.
New this day, ranked by depth score
The 12 that matter most of the 64 published.
CVE-2025-66301Critical· 9.6PoCGrav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the …
CVE-2025-3500Critical· 9.0PoCInteger Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.
Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.
CVE-2025-66294High· 8.8PoCGrav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …
CVE-2025-55749High· 7.5PoCXWiki is an open-source wiki software platform
XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder.…
CVE-2025-12106Critical· 9.1Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
CVE-2025-66299High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypas…
CVE-2025-66297High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, th…
CVE-2025-66295High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat)…
CVE-2025-66296High· 8.8Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permissio…
CVE-2025-66300High· 8.5Grav is a file-based Web platform
Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), w…
CVE-2025-66034Medium· 6.3PoCfontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
CVE-2025-55222High· 8.6A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send …
Most-affected vendors
By CVEs published in the period.