VulnSea

Daily digest

Monday 29 December 2025

A heavy day: 22 new CVEs, well above the recent average of about 8. Of those, 2 critical and 3 high. One arrived with exploitation evidence or public exploit code already attached. fabian was the most-affected vendor with 3.

22
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 22 published.

CVE-2025-68897Critical· 9.9
9mo ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I

Improper Control of Generation of Code ('Code Injection') vulnerability in Mohammad I. Okfie IF AS Shortcode if-as-shortcode allows Code Injection.This issue affects IF AS Shortcode: from n/a through <= 1.2.

▾ MidnightEPSS 0.33%via NVD
CVE-2025-68562Critical· 9.9
9mo ago

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through 8.7.3.

Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG allows Upload a Web Shell to a Web Server.This issue affects MapSVG: from n/a through 8.7.3.

▾ MidnightEPSS 0.42%via NVD
CVE-2025-14175Medium· 6.5PoC
9mo ago

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromi…

A vulnerability in the SSH server of TP-Link TL-WR820N v2.80 allows the use of a weak cryptographic algorithm, enabling an adjacent attacker to intercept and decrypt SSH traffic. Exploitation may expose sensitive information and compromi…

▾ Twilighttp-link · tl-wr820n_firmwareEPSS 0.30%via NVD
CVE-2025-15208High· 7.3
9mo ago

A security flaw has been discovered in code-projects Refugee Food Management System 1.0

A security flaw has been discovered in code-projects Refugee Food Management System 1.0. Affected by this issue is some unknown functionality of the file /home/editrefugee.php. The manipulation of the argument rfid results in sql injecti…

▾ Twilightfabian · refugee_food_management_systemEPSS 0.39%via NVD
CVE-2025-15207High· 7.3
9mo ago

A vulnerability has been found in Campcodes Supplier Management System 1.0

A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/view_products.php. The manipulation of the argument chkId[] leads to sql injection. It is possible to initiate…

▾ Twilightcampcodes · supplier_management_systemEPSS 0.51%via NVD
CVE-2025-15206High· 7.3
9mo ago

A flaw has been found in Campcodes Supplier Management System 1.0

A flaw has been found in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /admin/add_area.php. Executing a manipulation of the argument txtAreaCode can lead to sql injection. The attack may be perfor…

▾ Twilightcampcodes · supplier_management_systemEPSS 0.51%via NVD
CVE-2025-14728Medium· 6.8
9mo ago

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory

Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write …

▾ Sunlitrapid7 · velociraptorEPSS 0.56%via NVD
CVE-2025-69202Medium· 6.5
9mo ago

Axios Cache Interceptor is a cache interceptor for axios

Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor returns incorrect cached responses, leading to authorization …

▾ Sunlitaxios-cache-interceptor · axios_cache_interceptorEPSS 0.32%via NVD
CVE-2025-68607Medium· 6.5
9mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Stored XSS.This issue affects Custom Field Template: from n/a thro…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hiroaki Miyashita Custom Field Template custom-field-template allows Stored XSS.This issue affects Custom Field Template: from n/a thro…

▾ SunlitEPSS 0.20%via NVD
CVE-2025-68504Medium· 6.5
9mo ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.16.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSearch jet-search allows DOM-Based XSS.This issue affects JetSearch: from n/a through <= 3.5.16.

▾ SunlitEPSS 0.21%via NVD
CVE-2025-68503Medium· 6.5
9mo ago

Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.

Missing Authorization vulnerability in Crocoblock JetBlog jet-blog allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JetBlog: from n/a through <= 2.4.7.

▾ SunlitEPSS 0.31%via NVD
CVE-2025-69205Medium· 6.3
9mo ago

Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk

Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts a special federation name and character…

▾ SunlitEPSS 0.14%via NVD

Most-affected vendors

By CVEs published in the period.