VulnSea

Daily digest

Friday 19 December 2025

A quiet day: only 15 new CVEs against a recent average of about 31. Of those, 1 critical and 4 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

15
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this day, ranked by depth score

The 12 that matter most of the 15 published.

CVE-2025-14733Critical· 9.8CISA KEV0dayPoC
9mo ago

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…

▾ Hadalwatchguard · firewareEPSS 27%via NVD
CVE-2025-52692High· 8.8
9mo ago

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.

Successful exploitation of the vulnerability could allow an attacker with local network access to send a specially crafted URL to access certain administration functions without login credentials.

▾ Twilightlinksys · e9450-sg_firmwareEPSS 6.4%via NVD
CVE-2025-11774High· 8.2
9mo ago

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") of Mitsubishi Electric GENESIS64 versions 10.97.2 C…

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the software keyboard function (hereinafter referred to as "keypad function") of Mitsubishi Electric GENESIS64 versions 10.97.2 C…

▾ TwilightEPSS 0.57%via NVD
CVE-2025-68477High· 7.7
9mo ago

Langflow vulnerable to Server-Side Request Forgery

Langflow vulnerable to Server-Side Request Forgery

▾ Twilightlangflow · langflowEPSS 6.3%via OSV
CVE-2025-14151High· 7.2
9mo ago

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' parameter in the slimtrack AJAX action in all versions up to, and including, 5.3.2

The SlimStat Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'outbound_resource' parameter in the slimtrack AJAX action in all versions up to, and including, 5.3.2. This is due to insufficient input sa…

▾ TwilightEPSS 0.40%via NVD
CVE-2025-68383Medium· 6.5
9mo ago

Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration

Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration

▾ Sunlitelastic · github.com/elastic/beats/v7EPSS 0.19%via OSV
CVE-2025-66519Medium· 6.3
9mo ago

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Layer Import functionality. A crafted payload can be injected into the “Create new Layer” field during layer import and is later rendered into the…

▾ Sunlitfoxit · pdf_editor_cloudEPSS 0.18%via NVD
CVE-2025-66502Medium· 6.3
9mo ago

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature

A stored cross-site scripting (XSS) vulnerability exists in pdfonline.foxit.com within the Page Templates feature. A crafted payload can be stored as the template name, which is later rendered into the DOM without proper sanitization. As…

▾ Sunlitfoxit · pdf_editor_cloudEPSS 0.18%via NVD
CVE-2025-14546Medium· 6.3
9mo ago

FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation

FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validation

▾ Sunlitfastapi-sso · fastapi-ssoEPSS 0.36%via OSV
CVE-2025-68481Medium· 5.9
9mo ago

FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO

FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSO

▾ Sunlitfastapi-users · fastapi-usersEPSS 0.26%via OSV
CVE-2025-14946Medium· 4.8
9mo ago

A flaw was found in libnbd

A flaw was found in libnbd. A malicious actor could exploit this by convincing libnbd to open a specially crafted Uniform Resource Identifier (URI). This vulnerability arises because non-standard hostnames starting with '-o' are incorrec…

▾ SunlitEPSS 0.14%via NVD
CVE-2025-14962Medium· 4.3
9mo ago

A flaw has been found in code-projects Simple Stock System 1.0

A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file /market/chatuser.php. This manipulation causes cross site scripting. The attack is possible to be carried out remotel…

▾ Sunlitcarmelo · simple_stock_systemEPSS 0.33%via NVD

Most-affected vendors

By CVEs published in the period.