VulnSea

Daily digest

Wednesday 24 December 2025

22 new CVEs this day, in line with the recent average. Of those, 2 critical and 7 high. 3 arrived with exploitation evidence or public exploit code already attached. Linux was the most-affected vendor with 6.

22
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2018-25138Critical· 9.8PoC
9mo ago

FLIR AX8 Thermal Camera 1.32.16 Hard-Coded Credentials Authentication Bypass

FLIR AX8 Thermal Camera 1.32.16 contains hard-coded SSH and web panel credentials that cannot be changed through normal camera operations. Attackers can exploit these persistent credentials to gain unauthorized shell access and login to …

▾ AbyssalFLIR Systems · FLIR AX8 Thermal CameraEPSS 0.62%via CVEORG
CVE-2018-25135Critical· 9.8PoC
9mo ago

Anviz AIM CrossChex Standard 4.3.6.0 CSV Injection via User Import

Anviz AIM CrossChex Standard 4.3.6.0 contains a CSV injection vulnerability that allows attackers to execute commands by inserting malicious formulas in user import fields. Attackers can craft payloads in fields like 'Name', 'Gender', or…

▾ AbyssalAnviz Biometric Technology Co., Ltd. · Anviz AIM CrossChex StandardEPSS 0.70%via CVEORG
CVE-2018-25139High· 7.5PoC
9mo ago

FLIR AX8 Thermal Camera 1.32.16 Unauthenticated RTSP Stream Disclosure

FLIR AX8 Thermal Camera 1.32.16 contains an unauthenticated vulnerability that allows remote attackers to access live video streams without credentials. Attackers can directly connect to the RTSP stream using tools like VLC or FFmpeg to …

▾ MidnightFLIR Systems, Inc. · FLIR AX8 Thermal CameraEPSS 0.53%via CVEORG
CVE-2025-68736High· 8.8
9mo ago

In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories Disconnected files or directories can appear when they are visible and opened from a bind mount, but have been renam…

In the Linux kernel, the following vulnerability has been resolved: landlock: Fix handling of disconnected directories Disconnected files or directories can appear when they are visible and opened from a bind mount, but have been renam…

▾ TwilightLinux · LinuxEPSS 0.14%via NVD
CVE-2025-68590High· 7.6
9mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CRM Perks Integration for Contact Form 7 HubSpot cf7-hubspot allows Blind SQL Injection.This issue affects Integration for Contact Form…

▾ TwilightEPSS 0.33%via NVD
CVE-2025-68540High· 7.5
9mo ago

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35.

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Fana fana allows PHP Local File Inclusion.This issue affects Fana: from n/a through <= 1.1.35.

▾ TwilightEPSS 0.39%via NVD
CVE-2025-68349High· 7.5
9mo ago

NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid

In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid Fixes a crash when layout is null during this call stack: write_inode -> nfs4_write_ino…

▾ TwilightLinux · LinuxEPSS 0.69%via CVEORG
CVE-2025-2515High· 7.2
9mo ago

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS

A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user with root privileges on a managed node (qm) to create or override systemd service unit files that affect the host node.…

▾ TwilightEPSS 0.21%via NVD
CVE-2025-68724High· 7.1
9mo ago

kernel: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id (CVE-2025-68724)

In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id Use check_add_overflow() to guard against potential integer overflows when adding the binary blo…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.4)EPSS 0.14%via CSAF
CVE-2025-68598Medium· 6.5
9mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Compo…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder allows Stored XSS.This issue affects Page Builder: Live Compo…

▾ SunlitLive Composer Team · live-composer-page-builderEPSS 0.16%via NVD
CVE-2025-68597Medium· 6.5
9mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Stored XSS.This issue affects Jobs for WordPress: from n/a through <= 2…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlueGlass Interactive AG Jobs for WordPress job-postings allows Stored XSS.This issue affects Jobs for WordPress: from n/a through <= 2…

▾ SunlitEPSS 0.16%via NVD
CVE-2025-36154Medium· 6.2
9mo ago

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be obtained by a local user.

▾ Sunlitibm · concertEPSS 0.10%via NVD

Most-affected vendors

By CVEs published in the period.