VulnSea

Daily digest

Thursday 4 December 2025

A heavy day: 46 new CVEs, well above the recent average of about 24. Of those, 4 critical and 15 high. 3 arrived with exploitation evidence or public exploit code already attached. synology was the most-affected vendor with 12.

46
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 46 published.

CVE-2025-29268Critical· 9.8
10mo ago

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

▾ Midnightallnet · all-rut22gw_firmwareEPSS 8.5%via NVD
CVE-2025-40261Critical· 9.8
10mo ago

nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()

In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to complete before returning, and an error c…

▾ MidnightLinux · LinuxEPSS 0.56%via CVEORG
CVE-2025-29269Critical· 9.8
10mo ago

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

▾ Midnightallnet · all-rut22gw_firmwareEPSS 2.0%via NVD
CVE-2025-65945High· 7.5PoC
10mo ago

auth0/node-jws is a JSON Web Signature implementation for Node.js

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditi…

▾ Midnightauth0 · node-jwsEPSS 0.21%via NVD
CVE-2025-65637HighPoC
10mo ago

Logrus is vulnerable to DoS when using Entry.Writer()

Logrus is vulnerable to DoS when using Entry.Writer()

▾ Midnightsirupsen · github.com/sirupsen/logrusEPSS 0.63%via OSV
CVE-2024-45538Critical· 9.6
10mo ago

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute …

Cross-Site Request Forgery (CSRF) vulnerability in WebAPI Framework in Synology DiskStation Manager (DSM) before 7.2.1-69057-2 and 7.2.2-72806 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute …

▾ Midnightsynology · diskstation_managerEPSS 0.37%via NVD
CVE-2025-66287High· 8.8
10mo ago

A flaw was found in WebKitGTK

A flaw was found in WebKitGTK. Processing malicious web content can cause an unexpected process crash due to improper memory handling.

▾ TwilightEPSS 0.47%via NVD
CVE-2025-65958High· 8.5
10mo ago

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

▾ Twilightopen-webui · open-webuiEPSS 4.4%via OSV
CVE-2025-12995High· 8.1
10mo ago

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances

Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint that could be used to determine a valid password under certain circumstances. This issue affects CareLink Network: be…

▾ Twilightmedtronic · carelink_networkEPSS 0.33%via NVD
CVE-2025-66575High· 7.8
10mo ago

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges

VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service…

▾ Twilightveepn · veepnEPSS 0.46%via NVD
CVE-2025-54160High· 7.8
10mo ago

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

▾ Twilightsynology · beedriveEPSS 0.20%via NVD
CVE-2025-54158High· 7.8
10mo ago

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local users to execute arbitrary code via unspecified vectors.

▾ Twilightsynology · beedriveEPSS 0.18%via NVD

Most-affected vendors

By CVEs published in the period.