VulnSea

Daily digest

Friday 26 December 2025

10 new CVEs this day, in line with the recent average. Of those, 3 high. ibm was the most-affected vendor with 3.

10
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 10 that matter most of the 10 published.

CVE-2025-67729High· 8.8
9mo ago

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

▾ Twilightlmdeploy · lmdeployEPSS 0.60%via OSV
CVE-2025-68939High· 8.2
9mo ago

Gitea allows attackers to add attachments with forbidden file extensions

Gitea allows attackers to add attachments with forbidden file extensions

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.33%via OSV
CVE-2025-64645High· 7.7
9mo ago

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

IBM Concert 1.0.0 through 2.1.0 could allow a local user to escalate their privileges due to a race condition of a symbolic link.

▾ Twilightibm · concertEPSS 0.12%via NVD
CVE-2025-36192Medium· 6.7
9mo ago

IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt…

IBM DS8A00( R10.1) 10.10.106.0 and IBM DS8A00 ( R10.0) 10.1.3.010.2.45.0 and IBM DS8900F ( R9.4) 89.40.83.089.42.18.089.44.5.0 IBM System Storage DS8000 could allow a local user with authorized CCW update permissions to delete or corrupt…

▾ Sunlitibm · ds8a00_firmwareEPSS 0.11%via NVD
CVE-2025-15098Medium· 6.3
9mo ago

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11

A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the argument url/heade…

▾ SunlitEPSS 0.29%via NVD
CVE-2025-8075Medium· 5.4
9mo ago

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate

Cybersecurity Nozomi Networks Labs, a specialized security company focused on Industrial Control Systems (ICS) and OT/IoT security, has discovered that validation of incoming XML format request messages is inadequate. This vulnerability …

▾ Sunlithanwhavision · xno-8082r_firmwareEPSS 0.20%via NVD
CVE-2025-15094Medium· 4.3
9mo ago

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414

A weakness has been identified in sunkaifei FlyCMS up to abbaa5a8daefb146ad4d61027035026b052cb414. The impacted element is the function userLogin of the file src/main/java/com/flycms/web/front/UserController.java of the component User Lo…

▾ Sunlitsunkaifei · flycmsEPSS 0.39%via NVD
CVE-2025-14687Medium· 4.3
9mo ago

IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

IBM Db2 Intelligence Center 1.1.0, 1.1.1, 1.1.2 could allow an authenticated user to perform unauthorized actions due to client-side enforcement of sever side security mechanisms.

▾ Sunlitibm · db2_intelligence_centerEPSS 0.21%via NVD
MAL-2025-192943None
9mo ago

Malicious code in telegrem (PyPI)

Malicious code in telegrem (PyPI)

▾ Sunlittelegrem · telegremvia OSV
MAL-2025-192942None
9mo ago

Malicious code in telebot-bot (PyPI)

Malicious code in telebot-bot (PyPI)

▾ Sunlittelebot-bot · telebot-botvia OSV

Most-affected vendors

By CVEs published in the period.