VulnSea

Daily digest

Thursday 25 December 2025

A quiet day: only 5 new CVEs against a recent average of about 22. Severity skewed high: 3 high, 60% of the total. pexip was the most-affected vendor with 4.

5
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 5 that matter most of the 5 published.

CVE-2025-59683High· 8.2
9mo ago

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens

Pexip Infinity 15.0 through 38.0 before 38.1 has Improper Access Control in the Secure Scheduler for Exchange service, when used with Office 365 Legacy Exchange Tokens. This allows a remote attacker to read potentially sensitive data and…

▾ Twilightpexip · pexip_infinityEPSS 0.33%via NVD
CVE-2025-66379High· 7.5
9mo ago

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.

▾ Twilightpexip · pexip_infinityEPSS 0.37%via NVD
CVE-2025-66377High· 7.5
9mo ago

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operati…

Pexip Infinity before 39.0 has Missing Authentication for a Critical Function in a product-internal API, allowing an attacker (who already has access to execute code on one node within a Pexip Infinity installation) to impact the operati…

▾ Twilightpexip · pexip_infinityEPSS 0.21%via NVD
CVE-2025-49088Medium· 5.9
9mo ago

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a craf…

Pexip Infinity 32.0 through 37.1 before 37.2, in certain configurations of OTJ (One Touch Join) for Teams SIP Guest Join, has Improper Input Validation in the OTJ service, allowing a remote attacker to trigger a software abort via a craf…

▾ Sunlitpexip · pexip_infinityEPSS 0.32%via NVD
RUSTSEC-2025-0167None
9mo ago

`Bitmap::try_from(&[u8])` can create invalid values

`Bitmap::try_from(&[u8])` can create invalid values

▾ Sunlitbitmaps · bitmapsvia OSV

Most-affected vendors

By CVEs published in the period.