VulnSea

Daily digest

Friday 12 December 2025

35 new CVEs this day, in line with the recent average. Of those, 1 critical and 13 high. 4 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apple was the most-affected vendor with 12.

35
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 35 published.

CVE-2025-14174High· 8.8CISA KEV0dayPoC
9mo ago

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 22%via NVD
CVE-2025-43510High· 7.8CISA KEV
9mo ago

A memory corruption issue was addressed with improved lock state checking

A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26…

▾ Abyssalapple · ipadosEPSS 0.36%via NVD
CVE-2024-14010Critical· 9.8PoC
9mo ago

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF expor…

▾ AbyssalTypora · TyporaEPSS 1.2%via NVD
CVE-2025-43520Medium· 5.5CISA KEVPoC
9mo ago

A memory corruption issue was addressed with improved memory handling

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, …

▾ Midnightapple · ipadosEPSS 0.43%via NVD
CVE-2025-43539High· 8.8
9mo ago

The issue was addressed with improved bounds checks

The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Proc…

▾ Twilightapple · macosEPSS 6.2%via NVD
CVE-2025-12824High· 8.8
9mo ago

The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderboard' shortcode

The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderboard' shortcode. This is due to the plugin using an unsanitized user-supplied value from…

▾ TwilightEPSS 0.80%via NVD
CVE-2025-65530High· 8.8
9mo ago

An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.

An eval injection in the malware de-obfuscation routines of CloudLinux ai-bolit before v32.7.4 allows attackers to overwrite arbitrary files as root via scanning a crafted file.

▾ Twilightcloudlinux · ai-bolitEPSS 0.30%via NVD
CVE-2025-67508High· 8.4
9mo ago

gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools

gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. When using non‑POSIX shells such as Fish and PowerShell, versions 2.11.0 and below of gardenctl allow an attacker with …

▾ Twilightlinuxfoundation · gardenctlEPSS 0.24%via NVD
CVE-2025-46285High· 7.8
9mo ago

An integer overflow was addressed by adopting 64-bit timestamps

An integer overflow was addressed by adopting 64-bit timestamps. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.3, macOS Sonoma 14.8.3, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchO…

▾ Twilightapple · macosEPSS 0.19%via NVD
CVE-2025-36745High· 7.8
9mo ago

SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems

SolarEdge SE3680H  ships with an outdated Linux kernel containing unpatched vulnerabilities in core subsystems. An attacker with network or local access can exploit these flaws to achieve remote code execution, privilege escalation, or d…

▾ Twilightsolaredge · se3680h_firmwareEPSS 0.23%via NVD
CVE-2025-67726High· 7.5
9mo ago

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing…

Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httputil.…

▾ Twilighttornado · tornadoEPSS 0.53%via OSV
CVE-2025-67725High· 7.5
9mo ago

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP req…

Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method.…

▾ Twilighttornado · tornadoEPSS 0.56%via OSV

Most-affected vendors

By CVEs published in the period.