VulnSea

Daily digest

Tuesday 16 December 2025

42 new CVEs this day, in line with the recent average. Of those, 2 critical and 15 high. 5 arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 7.

42
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 42 published.

CVE-2023-53899Critical· 9.8PoC
9mo ago

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form

PodcastGenerator 3.2.9 contains a blind server-side request forgery vulnerability that allows attackers to inject XML in the episode upload form. Attackers can manipulate the 'shortdesc' parameter to trigger external HTTP requests to arb…

▾ Abyssalpodcastgenerator · podcast_generatorEPSS 0.57%via NVD
CVE-2025-65318Critical· 9.1PoC
9mo ago

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

▾ Abyssalcanarymail · canary_mailEPSS 0.56%via NVD
CVE-2025-14765High· 8.8PoC
9mo ago

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Use after free in WebGPU in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 3.0%via NVD
CVE-2025-14766High· 8.8
9mo ago

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Out of bounds read and write in V8 in Google Chrome prior to 143.0.7499.147 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 3.2%via NVD
CVE-2025-65427Medium· 6.5PoC
9mo ago

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

▾ Twilightdbitnet · dbit_n300_t1_pro_firmwareEPSS 0.27%via NVD
CVE-2025-68154High· 8.1
9mo ago

systeminformation is a System and OS information library for node.js

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is …

▾ Twilightsysteminformation · systeminformationEPSS 13%via NVD
CVE-2025-68054High· 8.5
9mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Background countdown_with_background allows Blind SQL Injection.This issue affects CountDown…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup CountDown With Image or Video Background countdown_with_background allows Blind SQL Injection.This issue affects CountDown…

▾ TwilightEPSS 0.24%via NVD
CVE-2025-68053High· 8.5
9mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows Blind SQL Injection.This issue affects xPromoter: from n/a through <= 1.3.4.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup xPromoter top_bar_promoter allows Blind SQL Injection.This issue affects xPromoter: from n/a through <= 1.3.4.

▾ TwilightEPSS 0.24%via NVD
CVE-2025-68265High· 7.8
9mo ago

nvme: fix admin request_queue lifetime

In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespaces can access the controller's admin request_queue, and stale references on the namespaces may exist after tearing d…

▾ TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2025-10898High· 7.8
9mo ago

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability

AA maliciously crafted MODEL file, when parsed through certain Autodesk products, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbit…

▾ Twilightautodesk · shared_componentsEPSS 0.26%via NVD
CVE-2025-10889High· 7.8
9mo ago

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability

A maliciously crafted CATPART file, when parsed through certain Autodesk products, can force a Memory corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current pro…

▾ Twilightautodesk · shared_componentsEPSS 0.26%via NVD
CVE-2025-10881High· 7.8
9mo ago

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability

A maliciously crafted CATPRODUCT file, when parsed through certain Autodesk products, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbi…

▾ Twilightautodesk · shared_componentsEPSS 0.28%via NVD

Most-affected vendors

By CVEs published in the period.