VulnSea

Daily digest

Sunday 14 December 2025

A quiet day: only 12 new CVEs against a recent average of about 50. Severity skewed high: 1 critical and 9 high, 83% of the total.

12
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 12 published.

CVE-2025-14665Critical· 9.8
9mo ago

A security flaw has been discovered in Tenda WH450 1.0.0.18

A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer ov…

▾ Midnighttenda · wh450_firmwareEPSS 0.98%via NVD
CVE-2025-14655High· 8.8
9mo ago

A security flaw has been discovered in Tenda AC20 16.03.08.12

A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd. Performing a manipulation of the argument rebootTime r…

▾ Twilighttenda · ac20_firmwareEPSS 3.3%via NVD
CVE-2025-14673High· 7.3
9mo ago

A vulnerability has been found in gmg137 snap7-rs up to 1.142.1

A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based buffer overflow. The attack…

▾ Twilightgmg137 · snap7-rsEPSS 0.49%via NVD
CVE-2025-14672High· 7.3
9mo ago

A flaw has been found in gmg137 snap7-rs up to 1.142.1

A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch t…

▾ Twilightgmg137 · snap7-rsEPSS 0.49%via NVD
CVE-2025-14668High· 7.3
9mo ago

A vulnerability was detected in campcodes Advanced Online Examination System 1.0

A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possib…

▾ Twilightcampcodes · advanced_online_examination_systemEPSS 0.39%via NVD
CVE-2025-14667High· 7.3
9mo ago

A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0

A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/?page=system_info. Such manipulation of the argument meta_value leads to sql injection. …

▾ Twilightangeljudesuarez · covid_tracking_systemEPSS 0.39%via NVD
CVE-2025-14666High· 7.3
9mo ago

A weakness has been identified in itsourcecode COVID Tracking System 1.0

A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. This manipulation of the argument Username causes sql injection. The attack is possible …

▾ Twilightangeljudesuarez · covid_tracking_systemEPSS 0.39%via NVD
CVE-2025-14664High· 7.3
9mo ago

A vulnerability was identified in Campcodes Supplier Management System 1.0

A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument chkId[] leads to sql injection. Remote exploitation…

▾ Twilightcampcodes · supplier_management_systemEPSS 0.39%via NVD
CVE-2025-14652High· 7.3
9mo ago

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0

A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may …

▾ Twilightadmerc · online_cake_ordering_systemEPSS 0.39%via NVD
CVE-2025-14650High· 7.3
9mo ago

A flaw has been found in itsourcecode Online Cake Ordering System 1.0

A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing manipulation of the argument Product can lead to sql injection. The attack can be launched r…

▾ Twilightadmerc · online_cake_ordering_systemEPSS 0.40%via NVD
CVE-2025-14674Medium· 6.3
9mo ago

A vulnerability was found in aizuda snail-job up to 1.6.0

A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/…

▾ SunlitEPSS 0.33%via NVD
CVE-2025-14660Medium· 5.6
9mo ago

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31

A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argum…

▾ SunlitEPSS 0.32%via NVD

Most-affected vendors

By CVEs published in the period.