VulnSea

Daily digest

Monday 1 December 2025

A heavy day: 64 new CVEs, well above the recent average of about 6. Severity skewed high: 3 critical and 31 high, 53% of the total. 6 arrived with exploitation evidence or public exploit code already attached. getgrav was the most-affected vendor with 15.

64
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 64 published.

CVE-2025-66301Critical· 9.6PoC
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the …

▾ Abyssalgetgrav · gravEPSS 1.3%via NVD
CVE-2025-3500Critical· 9.0PoC
10mo ago

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

▾ Abyssalavast · antivirusEPSS 0.46%via NVD
CVE-2025-66294High· 8.8PoC
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a Server-Side Template Injection (SSTI) vulnerability exists in Grav that allows authenticated attackers with editor permissions to execute arbitrary commands on the server and, …

▾ Midnightgetgrav · gravEPSS 2.8%via NVD
CVE-2025-55749High· 7.5PoC
10mo ago

XWiki is an open-source wiki software platform

XWiki is an open-source wiki software platform. From 16.7.0 to 16.10.11, 17.4.4, or 17.7.0, in an instance which is using the XWiki Jetty package (XJetty), a context is exposed to statically access any file located in the webapp/ folder.…

▾ Midnightxwiki · xwikiEPSS 1.5%via NVD
CVE-2025-12106Critical· 9.1
10mo ago

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

▾ Midnightopenvpn · openvpnEPSS 0.56%via NVD
CVE-2025-66299High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypas…

▾ Twilightgetgrav · gravEPSS 0.61%via NVD
CVE-2025-66297High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a user with admin panel access and permissions to create or edit pages in Grav CMS can enable Twig processing in the page frontmatter. By injecting malicious Twig expressions, th…

▾ Twilightgetgrav · gravEPSS 0.78%via NVD
CVE-2025-66295High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, when a user with privilege of user creation creates a new user through the Admin UI and supplies a username containing path traversal sequences (for example ..\Nijat or ../Nijat)…

▾ Twilightgetgrav · gravEPSS 0.55%via NVD
CVE-2025-66296High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, a privilege escalation vulnerability exists in Grav’s Admin plugin due to the absence of username uniqueness validation when creating users. A user with the create user permissio…

▾ Twilightgetgrav · gravEPSS 0.32%via NVD
CVE-2025-66300High· 8.5
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, A low privilege user account with page editing privilege can read any server files using "Frontmatter" form. This includes Grav user account files (/grav/user/accounts/*.yaml), w…

▾ Twilightgetgrav · gravEPSS 0.45%via NVD
CVE-2025-66034Medium· 6.3PoC
10mo ago

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

▾ Twilightfonttools · fonttoolsEPSS 0.55%via OSV
CVE-2025-55222High· 8.6
10mo ago

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send …

▾ Twilightsocomec · diris_m-70_firmwareEPSS 0.42%via NVD

Most-affected vendors

By CVEs published in the period.