VulnSea

Daily digest

Tuesday 9 December 2025

A heavy day: 104 new CVEs, well above the recent average of about 43. Severity skewed high: 6 critical and 58 high, 62% of the total. 6 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. microsoft was the most-affected vendor with 26.

104
New CVEs
6
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 104 published.

CVE-2025-62221High· 7.8CISA KEV0dayPoC
10mo ago

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

▾ Abyssalmicrosoft · windows_10_1809EPSS 2.5%via NVD
CVE-2025-66039Critical· 9.8PoC
10mo ago

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an…

▾ Abyssalsangoma · freepbxEPSS 3.3%via NVD
CVE-2025-14321Critical· 9.8PoC
10mo ago

Use-after-free in the WebRTC: Signaling component

Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

▾ Abyssalmozilla · firefoxEPSS 0.60%via NVD
CVE-2025-62470High· 7.8PoC
10mo ago

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.51%via NVD
CVE-2025-54100High· 7.8PoC
10mo ago

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.

Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.

▾ Midnightmicrosoft · windows_10_1607EPSS 2.2%via NVD
CVE-2025-66631Critical· 9.8
10mo ago

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications

CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Versions 5.5.4 and below allow the use of WcfProxy. WcfProxy uses the now-obsolete NetDataContractSerializer (NDCS) and …

▾ Midnightcslanet · csla_.netEPSS 0.67%via NVD
CVE-2025-14330Critical· 9.8
10mo ago

JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

▾ Midnightmozilla · firefoxEPSS 0.51%via NVD
CVE-2025-14326Critical· 9.8
10mo ago

Use-after-free in the Audio/Video: GMP component

Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

▾ Midnightmozilla · firefoxEPSS 0.46%via NVD
CVE-2025-14324Critical· 9.8
10mo ago

JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

▾ Midnightmozilla · firefoxEPSS 0.56%via NVD
CVE-2025-14325High· 7.3PoC
10mo ago

JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

▾ Midnightmozilla · firefoxEPSS 0.34%via NVD
CVE-2025-62549High· 8.8
10mo ago

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.3%via NVD
CVE-2025-62456High· 8.8
10mo ago

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_11_23h2EPSS 1.1%via NVD

Most-affected vendors

By CVEs published in the period.