VulnSea

Daily digest

Friday 5 December 2025

A heavy day: 56 new CVEs, well above the recent average of about 30. Of those, 2 critical and 24 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apache was the most-affected vendor with 3.

56
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 56 published.

CVE-2025-34291High· 8.8CISA KEVPoC
10mo ago

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a …

▾ Abyssallangflow · langflowEPSS 93%via NVD
CVE-2025-58098High· 8.3PoC
10mo ago

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. User…

Apache HTTP Server 2.4.65 and earlier with Server Side Includes (SSI) enabled and mod_cgid (but not mod_cgi) passes the shell-escaped query string to #exec cmd="..." directives. This issue affects Apache HTTP Server before 2.4.66. User…

▾ Midnightapache · http_serverEPSS 1.4%via NVD
CVE-2025-13313Critical· 9.8
10mo ago

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6

The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to, and including, 2.6. This is due to missing authorization and authentication checks on the `ntzcrm_changepassword` AJ…

▾ MidnightEPSS 0.55%via NVD
CVE-2025-66562Critical· 9.6
10mo ago

TUUI is a desktop MCP client designed as a tool unitary utility integration

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exists in Tuui due to an unsafe Cross-Site Scripting (XSS) flaw in the Markdown rendering c…

▾ Midnightaiql · tuuiEPSS 0.52%via NVD
CVE-2025-14107High· 8.8
10mo ago

A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050

A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function zfilev2_api.SafeStatus of the file /v2/file/safe/status of the component HTTP POST Request Handler. The manipulation …

▾ Twilightzspace · q2c_nas_firmwareEPSS 12%via NVD
CVE-2025-14106High· 8.8
10mo ago

A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050

A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of the file /v2/file/safe/close of the component HTTP POST Request Handler. The manipulation of the argument safe_dir lead…

▾ Twilightzspace · q2c_nas_firmwareEPSS 12%via NVD
CVE-2025-14108High· 8.8
10mo ago

A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050

A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.OpenSafe of the file /v2/file/safe/open of the component HTTP POST Request Handler. This manipulation of the argument …

▾ Twilightzspace · q2c_nas_firmwareEPSS 10%via NVD
CVE-2025-65897High· 8.8
10mo ago

zdh_web is a data collection, processing, monitoring, scheduling, and management platform

zdh_web is a data collection, processing, monitoring, scheduling, and management platform. In zdh_web thru 5.6.17, insufficient validation of file upload paths in the application allows an authenticated user to write arbitrary files to t…

▾ Twilightzhaoyachao · zdh_webEPSS 0.75%via NVD
CVE-2025-13066High· 8.8
10mo ago

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6

The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.0.6. This is due to insufficient file type validation detecting WXR files, allowing double extension files to bypa…

▾ TwilightEPSS 0.55%via NVD
CVE-2025-12153High· 8.8
10mo ago

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 0.1

The Featured Image via URL plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation function in all versions up to, and including, 0.1. This makes it possible for authenticated attackers, with Cont…

▾ TwilightEPSS 0.55%via NVD
CVE-2025-12879High· 8.8
10mo ago

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2

The User Generator and Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.2.2. This is due to missing nonce validation in the "Import Using CSV File" function. This makes it possib…

▾ TwilightEPSS 0.18%via NVD
CVE-2025-12163Medium· 6.4PoC
10mo ago

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping

The Omnipress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authe…

▾ TwilightEPSS 0.36%via NVD

Most-affected vendors

By CVEs published in the period.