VulnSea

Daily digest

Wednesday 10 December 2025

A heavy day: 130 new CVEs, well above the recent average of about 48. Of those, 14 critical and 34 high. 9 arrived with exploitation evidence or public exploit code already attached. adobe was the most-affected vendor with 76.

130
New CVEs
14
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 130 published.

CVE-2020-36894Critical· 9.3PoC
9mo ago

Eibiz i-Media Server Digital Signage 3.8.0 Unauthenticated User Creation Vulnerability

Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects…

▾ AbyssalEIBIZ Co.,Ltd. · i-Media Server Digital SignageEPSS 0.80%via CVEORG
CVE-2020-36892Critical· 9.3PoC
9mo ago

Eibiz i-Media Server Digital Signage 3.8.0 Unauthenticated Privilege Escalation

Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to eleva…

▾ AbyssalEIBIZ Co.,Ltd. · i-Media Server Digital SignageEPSS 1.1%via CVEORG
CVE-2025-65950High· 8.8PoC
9mo ago

WBCE CMS is a content management system

WBCE CMS is a content management system. In versions 1.6.4 and below, the user management module allows a low-privileged authenticated user with permissions to modify users to execute arbitrary SQL queries. This can be escalated to a ful…

▾ Midnightwbce · wbce_cmsEPSS 0.54%via NVD
CVE-2020-36895High· 8.7PoC
9mo ago

EIBIZ i-Media Server Digital Signage 3.8.0 Unauthenticated Configuration Disclosure

EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the Si…

▾ MidnightEIBIZ Co.,Ltd. · i-Media Server Digital SignageEPSS 0.73%via CVEORG
CVE-2020-36893High· 8.7PoC
9mo ago

Eibiz i-Media Server Digital Signage 3.8.0 Directory Traversal Vulnerability

Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter t…

▾ MidnightEIBIZ Co.,Ltd. · i-Media Server Digital SignageEPSS 1.6%via CVEORG
CVE-2025-13184Critical· 9.8
9mo ago

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution)

Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank password on factory/reset X5000R V9.1.0u.6369_B20230113 (arbitrary command execution). Earlier versions that share the sam…

▾ Midnighttotolink · x5000r_firmwareEPSS 11%via NVD
CVE-2025-65823Critical· 9.8
9mo ago

The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on

The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain una…

▾ Midnightmeatmeet · meatmeet_pro_wifi_&_bluetooth_meat_thermometer_firmwareEPSS 0.43%via NVD
CVE-2025-65294Critical· 9.8
9mo ago

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

▾ Midnightaqara · hub_m2_firmwareEPSS 0.98%via NVD
CVE-2025-41732Critical· 9.8
9mo ago

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

▾ Midnightwago · 0852-1328_firmwareEPSS 0.43%via NVD
CVE-2025-41730Critical· 9.8
9mo ago

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary data into fixed-size stack buffers which leads to full device compromise.

▾ Midnightwago · 0852-1328_firmwareEPSS 0.43%via NVD
CVE-2025-13339High· 7.5PoC
9mo ago

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function

The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.1 via the template_redirect() function. This makes it possible for unauthenticated attackers to read the…

▾ MidnightEPSS 2.2%via NVD
CVE-2025-67644High· 7.3PoC
9mo ago

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list method

▾ Midnightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 2.3%via OSV

Most-affected vendors

By CVEs published in the period.