Daily digest
Sunday 14 December 2025
A quiet day: only 12 new CVEs against a recent average of about 50. Severity skewed high: 1 critical and 9 high, 83% of the total.
New this day, ranked by depth score
The 12 that matter most of the 12 published.
CVE-2025-14665Critical· 9.8A security flaw has been discovered in Tenda WH450 1.0.0.18
A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer ov…
CVE-2025-14655High· 8.8A security flaw has been discovered in Tenda AC20 16.03.08.12
A security flaw has been discovered in Tenda AC20 16.03.08.12. The impacted element is the function formSetRebootTimer of the file /goform/SetSysAutoRebbotCfg of the component httpd. Performing a manipulation of the argument rebootTime r…
CVE-2025-14673High· 7.3A vulnerability has been found in gmg137 snap7-rs up to 1.142.1
A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to heap-based buffer overflow. The attack…
CVE-2025-14672High· 7.3A flaw has been found in gmg137 snap7-rs up to 1.142.1
A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffer overflow. It is possible to launch t…
CVE-2025-14668High· 7.3A vulnerability was detected in campcodes Advanced Online Examination System 1.0
A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possib…
CVE-2025-14667High· 7.3A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0
A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/?page=system_info. Such manipulation of the argument meta_value leads to sql injection. …
CVE-2025-14666High· 7.3A weakness has been identified in itsourcecode COVID Tracking System 1.0
A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. This manipulation of the argument Username causes sql injection. The attack is possible …
CVE-2025-14664High· 7.3A vulnerability was identified in Campcodes Supplier Management System 1.0
A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument chkId[] leads to sql injection. Remote exploitation…
CVE-2025-14652High· 7.3A vulnerability was found in itsourcecode Online Cake Ordering System 1.0
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may …
CVE-2025-14650High· 7.3A flaw has been found in itsourcecode Online Cake Ordering System 1.0
A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing manipulation of the argument Product can lead to sql injection. The attack can be launched r…
CVE-2025-14674Medium· 6.3A vulnerability was found in aizuda snail-job up to 1.6.0
A vulnerability was found in aizuda snail-job up to 1.6.0. Affected by this vulnerability is the function QLExpressEngine.doEval of the file snail-job-common/snail-job-common-core/src/main/java/com/aizuda/snailjob/common/core/expression/…
CVE-2025-14660Medium· 5.6A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31
A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31. Affected by this vulnerability is the function createTool of the file packages/sdk/src/mcp/teams/api.ts of the component Workspace Domain Handler. This manipulation of the argum…
Most-affected vendors
By CVEs published in the period.