VulnSea

Daily digest

Sunday 21 December 2025

A quiet day: only 5 new CVEs against a recent average of about 25. Severity skewed high: 5 high, 100% of the total. One arrived with exploitation evidence or public exploit code already attached.

5
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 5 that matter most of the 5 published.

CVE-2025-14855High· 7.2PoC
9mo ago

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping

The SureForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form field parameters in all versions up to, and including, 2.2.0 due to insufficient input sanitization and output escaping. This makes it possible …

▾ MidnightEPSS 0.37%via NVD
CVE-2025-14995High· 8.8
9mo ago

A vulnerability has been found in Tenda FH1201 1.2.0.14(408)

A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from r…

▾ Twilighttenda · fh1201_firmwareEPSS 0.74%via NVD
CVE-2025-14993High· 8.8
9mo ago

A vulnerability was detected in Tenda AC18 15.03.05.05

A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation of the argument scanList results in stack-based buffer overf…

▾ Twilighttenda · ac18_firmwareEPSS 0.78%via NVD
CVE-2025-14800High· 8.1
9mo ago

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7

The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_file_to_upload' function in all versions up to, and including, 3.2.7. This makes it possible…

▾ TwilightEPSS 0.39%via NVD
CVE-2025-9343High· 7.2
9mo ago

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output e…

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ticket subjects in all versions up to, and including, 3.3.4 due to insufficient input sanitization and output e…

▾ TwilightEPSS 0.23%via NVD

Most-affected vendors

By CVEs published in the period.