VulnSea

Daily digest

Thursday 11 December 2025

41 new CVEs this day, in line with the recent average. Of those, 2 critical and 16 high. 4 arrived with exploitation evidence or public exploit code already attached. google was the most-affected vendor with 22.

41
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 41 published.

CVE-2025-36937Critical· 9.8
9mo ago

In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check

In AudioDecoder::HandleProduceRequest of audio_decoder.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interactio…

▾ Midnightgoogle · androidEPSS 0.27%via NVD
CVE-2025-66589Critical· 9.1
9mo ago

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer

In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose informa…

▾ Midnightazeotech · daqfactoryEPSS 0.35%via NVD
CVE-2024-8273High· 8.8
9mo ago

Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.

Authentication Bypass by Spoofing vulnerability in HYPR Server allows Identity Spoofing.This issue affects Server: before 10.1.

▾ Twilighthypr · hypr_serverEPSS 0.31%via NVD
CVE-2024-58304Medium· 6.1PoC
9mo ago

SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts

SPA-CART CMS before 2.0.0 contains a stored cross-site scripting vulnerability in the product description parameter that allows authenticated administrators to inject malicious scripts. Attackers can submit JavaScript payloads through th…

▾ TwilightSPA-Cart · SPA-CART CMSEPSS 0.31%via NVD
CVE-2025-14523High· 8.2
9mo ago

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing

A flaw in libsoup’s HTTP header handling allows multiple Host: headers in a request and returns the last occurrence for server-side processing. Common front proxies often honor the first Host: header, so this mismatch can cause vhost con…

▾ TwilightEPSS 0.54%via NVD
CVE-2025-36924High· 8.0
9mo ago

In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check

In ss_DecodeLcsAssistDataReqMsg(void) of ss_LcsManagement.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution pri…

▾ Twilightgoogle · androidEPSS 0.12%via NVD
CVE-2025-36923High· 8.0
9mo ago

In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow

In NrmmDecoder::DecodeSORTransparentContext of cn_NrmmDecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution …

▾ Twilightgoogle · androidEPSS 0.13%via NVD
CVE-2025-36936High· 7.8
9mo ago

In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow

In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2025-36935High· 7.8
9mo ago

In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data

In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not n…

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2025-36932High· 7.8
9mo ago

In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation

In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges need…

▾ Twilightgoogle · androidEPSS 0.10%via NVD
CVE-2025-36931High· 7.8
9mo ago

In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check

In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

▾ Twilightgoogle · androidEPSS 0.08%via NVD
CVE-2025-36930High· 7.8
9mo ago

In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check

In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

▾ Twilightgoogle · androidEPSS 0.10%via NVD

Most-affected vendors

By CVEs published in the period.