VulnSea

Daily digest

Thursday 18 December 2025

A busier-than-usual day with 60 new CVEs (recent average about 40). Severity skewed high: 9 critical and 34 high, 72% of the total. 3 arrived with exploitation evidence or public exploit code already attached. axiomthemes was the most-affected vendor with 3.

60
New CVEs
9
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 60 published.

CVE-2025-68461High· 7.2CISA KEVPoC
9mo ago

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

▾ AbyssalRoundcube · WebmailEPSS 27%via CVEORG
CVE-2025-64374Critical· 9.9
9mo ago

Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through <= 5.6.81.

Unrestricted Upload of File with Dangerous Type vulnerability in StylemixThemes Motors motors allows Using Malicious Files.This issue affects Motors: from n/a through <= 5.6.81.

▾ MidnightEPSS 0.36%via NVD
CVE-2025-64231Critical· 9.9
9mo ago

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contac…

Unrestricted Upload of File with Dangerous Type vulnerability in RedefiningTheWeb WordPress Contact Form 7 PDF, Google Sheet & Database rtwwcfp-wordpress-contact-form-7-pdf allows Using Malicious Files.This issue affects WordPress Contac…

▾ MidnightEPSS 0.32%via NVD
CVE-2023-53937High· 7.8PoC
9mo ago

Hubstaff 1.6.14 DLL Search Order Hijacking via wow64log Library

Hubstaff 1.6.14 contains a DLL search order hijacking vulnerability that allows attackers to replace a missing system32 wow64log.dll with a malicious library. Attackers can generate a custom DLL using Metasploit and place it in the syste…

▾ MidnightHubstaff · HubstaffEPSS 0.22%via CVEORG
CVE-2025-64233Critical· 9.8
9mo ago

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.

Deserialization of Untrusted Data vulnerability in BoldThemes Codiqa codiqa allows Object Injection.This issue affects Codiqa: from n/a through < 1.2.8.

▾ MidnightEPSS 0.38%via NVD
CVE-2025-64227Critical· 9.8
9mo ago

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

Deserialization of Untrusted Data vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Object Injection.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.7.

▾ MidnightEPSS 0.38%via NVD
CVE-2025-64188Critical· 9.8
9mo ago

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.

Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.

▾ MidnightEPSS 0.43%via NVD
CVE-2025-14860Critical· 9.8
9mo ago

Use-after-free in the Disability Access APIs component

Use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 146.0.1.

▾ Midnightmozilla · firefoxEPSS 0.32%via NVD
CVE-2025-14437High· 7.5PoC
9mo ago

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function

The Hummingbird Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.18.0 via the 'request' function. This makes it possible for unauthenticated attackers to extract sen…

▾ MidnightEPSS 1.9%via NVD
CVE-2025-63389Critical
9mo ago

Ollama Platform has missing authentication enabling attackers to perform model management operations

Ollama Platform has missing authentication enabling attackers to perform model management operations

▾ Midnightollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2025-68398Critical· 9.1
9mo ago

Weblate is a web based localization tool

Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

▾ Midnightweblate · weblateEPSS 0.79%via NVD
CVE-2025-34449Critical· 9.1
9mo ago

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function

Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability in the sc_device_msg_deserialize() function. A compromised device can send crafted messages that cause out-of-bounds r…

▾ Midnightgenymotion · scrcpyEPSS 0.42%via NVD

Most-affected vendors

By CVEs published in the period.