VulnSea

Daily digest

Monday 15 December 2025

A quiet day: only 13 new CVEs against a recent average of about 51. Of those, 2 critical and 2 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

13
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2025-14708Critical· 9.8
9mo ago

A weakness has been identified in Shiguangwu sgwbox N3 2.0.25

A weakness has been identified in Shiguangwu sgwbox N3 2.0.25. Affected by this vulnerability is an unknown functionality of the file /usr/sbin/http_eshell_server of the component WIREDCFGGET Interface. Executing manipulation of the argu…

▾ Midnightsgwbox · n3_firmwareEPSS 6.5%via NVD
CVE-2025-13888Critical· 9.1
9mo ago

A flaw was found in OpenShift GitOps

A flaw was found in OpenShift GitOps. Namespace admins can create ArgoCD Custom Resources (CRs) that trick the system into granting them elevated permissions in other namespaces, including privileged namespaces. An authenticated attacker…

▾ MidnightEPSS 0.69%via NVD
CVE-2025-11393High· 8.7
9mo ago

A flaw was found in runtimes-inventory-rhel8-operator

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of o…

▾ TwilightEPSS 0.20%via NVD
CVE-2025-67906Medium· 5.4PoC
9mo ago

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

In MISP before 2.5.28, app/View/Elements/Workflows/executionPath.ctp allows XSS in the workflow execution path.

▾ Twilightmisp-project · mispEPSS 0.33%via NVD
CVE-2025-67747High
9mo ago

Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules list

▾ Twilightfickling · ficklingEPSS 0.28%via OSV
CVE-2025-37731Medium· 6.8
9mo ago

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates

▾ Sunlitelasticsearch · org.elasticsearch.plugin:x-pack-securityEPSS 0.19%via GHSA
CVE-2025-11670Medium· 6.4
9mo ago

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure.  This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.

▾ Sunlitzohocorp · manageengine_admanager_plusEPSS 0.44%via NVD
CVE-2025-65835Medium· 6.2
9mo ago

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter…

The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an exported broadcast receiver nl.xservices.plugins.ShareChooserPendingIntent with an android.intent.action.SEND intent filter…

▾ Sunliteddyverbruggen · cordova-plugin-x-socialsharingEPSS 0.28%via NVD
CVE-2025-14696Medium· 5.3
9mo ago

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3

A vulnerability was identified in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this vulnerability is an unknown functionality of the file /api/GylOperator/UpdatePasswordBatch. The manipul…

▾ SunlitEPSS 0.33%via NVD
CVE-2025-64725Low
9mo ago

Weblate has improper validation upon invitation acceptance

Weblate has improper validation upon invitation acceptance

▾ Sunlitweblate · weblateEPSS 0.35%via OSV
CVE-2025-34180None
9mo ago

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components

NetSupport Manager < 14.12.0001 relies on a shared Gateway Key for authentication between Manager/Control, Client, and Connectivity Server components. The key is stored using a reversible encoding scheme. An attacker who obtains access …

▾ SunlitEPSS 0.18%via NVD
CVE-2025-13824None
9mo ago

A security issue exists due to improper handling of malformed CIP packets during fuzzing

A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault…

▾ SunlitEPSS 0.34%via NVD

Most-affected vendors

By CVEs published in the period.