VulnSea

Daily digest

Wednesday 17 December 2025

41 new CVEs this day, in line with the recent average. Of those, 5 critical and 11 high. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apple was the most-affected vendor with 11.

41
New CVEs
5
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 41 published.

CVE-2025-59374Critical· 9.8CISA KEV0day
9mo ago

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting…

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting…

▾ Hadalasus · live_updateEPSS 1.2%via NVD
CVE-2025-43529High· 8.8CISA KEV0dayPoC
9mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malici…

▾ Abyssalapple · safariEPSS 8.8%via NVD
CVE-2025-68109Critical· 9.1PoC
9mo ago

ChurchCRM is an open-source church management system

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality does not validate the content or file extension of uploaded files. As a result, an attacker can upload a web shell file …

▾ Abyssalchurchcrm · churchcrmEPSS 1.5%via NVD
CVE-2025-67791Critical· 9.8
9mo ago

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*

An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete configuration (agent authentication) in DriveLock tenant allows attackers to impersonate any DriveLock agent on the net…

▾ Midnightdrivelock · drivelockEPSS 0.37%via NVD
CVE-2025-67787Critical· 9.6
9mo ago

An issue was discovered in 25.1.2 before 25.1.5

An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allows for session takeover over a network.

▾ Midnightdrivelock · drivelockEPSS 0.26%via NVD
CVE-2025-68145Critical· 9.1
9mo ago

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actual…

In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operations to a specific repository path, it did not validate that repo_path arguments in subsequent tool calls were actual…

▾ Midnightlfprojects · model_context_protocol_serversEPSS 7.0%via NVD
CVE-2025-68143High· 8.8
9mo ago

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP)

Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). In mcp-server-git versions prior to 2025.9.25, the git_init tool accepted arbitrary filesystem paths and created Git reposi…

▾ Twilightlfprojects · model_context_protocol_serversEPSS 8.1%via NVD
CVE-2025-46281High· 8.8
9mo ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to break out of its sandbox.

▾ Twilightapple · macosEPSS 0.20%via NVD
CVE-2025-34437High· 8.8
9mo ago

AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users

AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentication but omits ownership checks, allowing attackers to perform unauthorized uploads to …

▾ Twilightwwbn · avideoEPSS 0.40%via NVD
CVE-2023-53908High· 8.8
9mo ago

HiSecOS 04.0.01 Privilege Escalation via User Role Modification

HiSecOS 04.0.01 contains a privilege escalation vulnerability that allows authenticated users to modify their access role through XML-based NETCONF configuration. Attackers can send crafted XML payloads to the /mops_data endpoint with a …

▾ TwilightBelden · HiSecOSEPSS 0.34%via CVEORG
CVE-2025-34438High· 8.1
9mo ago

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce own…

▾ Twilightwwbn · avideoEPSS 0.28%via NVD
CVE-2025-46291High· 7.8
9mo ago

A logic issue was addressed with improved validation

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

▾ Twilightapple · macosEPSS 0.20%via NVD

Most-affected vendors

By CVEs published in the period.