VulnSea

Daily digest

Monday 22 December 2025

18 new CVEs this day, in line with the recent average. Severity skewed high: 8 critical and 6 high, 78% of the total. 9 arrived with exploitation evidence or public exploit code already attached. SOUND4 Ltd. was the most-affected vendor with 6.

18
New CVEs
8
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2023-53963Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and …

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.4%via CVEORG
CVE-2025-65856Critical· 9.8PoC
9mo ago

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF i…

▾ Abyssalxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.74%via NVD
CVE-2023-53964Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint wi…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.98%via CVEORG
CVE-2023-53960Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x SQL Injection via Authentication Bypass

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'pas…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.74%via CVEORG
CVE-2023-53955Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.85%via CVEORG
CVE-2025-67288Critical· 10.0
9mo ago

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in …

▾ Midnightumbraco · umbraco_cmsEPSS 0.55%via NVD
CVE-2025-67289Critical· 9.6
9mo ago

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

▾ Midnightfrappe · erpnextEPSS 0.46%via NVD
CVE-2025-65857High· 7.5PoC
9mo ago

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

▾ Midnightxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.43%via NVD
CVE-2024-27708Critical· 9.6
9mo ago

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.

Iframe injection vulnerability in airc.pt/solucoes-servicos.solucoes MyNET v.26.06 and before allows a remote attacker to execute arbitrary code via the src parameter.

▾ Midnightairc · mynetEPSS 0.61%via NVD
CVE-2023-53974High· 7.5PoC
9mo ago

D-Link DSL-124 ME_1.00 Backup Configuration File Disclosure via Unauthenticated Request

D-Link DSL-124 ME_1.00 contains a configuration file disclosure vulnerability that allows unauthenticated attackers to retrieve router settings through a POST request. Attackers can send a specific POST request to the router's configurat…

▾ MidnightD-Link · DSL-124 Wireless N300 ADSL2+EPSS 0.53%via CVEORG
CVE-2023-53962High· 7.5PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 1.2%via CVEORG
CVE-2025-68475High· 7.5
9mo ago

Fedify is a TypeScript library for building federated server apps powered by ActivityPub

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Fedify's document loade…

▾ Twilightfedify · fedifyEPSS 0.56%via NVD

Most-affected vendors

By CVEs published in the period.