VulnSea

Daily digest

Tuesday 30 December 2025

A heavy day: 73 new CVEs, well above the recent average of about 10. Of those, 9 critical and 25 high. 16 arrived with exploitation evidence or public exploit code already attached. SOUND4 Ltd. was the most-affected vendor with 13.

73
New CVEs
9
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 73 published.

CVE-2022-50794Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands throug…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.7%via CVEORG
CVE-2025-50343Critical· 9.8PoC
9mo ago

An issue was discovered in matio 1.5.28

An issue was discovered in matio 1.5.28. A heap-based memory corruption can occur in Mat_VarCreateStruct() when the nfields value does not match the actual number of strings in the fields array. This leads to out-of-bounds reads and inva…

▾ Abyssalmatio_project · matioEPSS 0.41%via NVD
CVE-2023-53983Critical· 9.8PoC
9mo ago

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed

Anevia Flamingo XL/XS 3.6.20 contains a critical vulnerability with weak default administrative credentials that can be easily guessed. Attackers can leverage these hard-coded credentials to gain full remote system control without comple…

▾ Abyssalateme · soapliveEPSS 0.65%via NVD
CVE-2022-50796Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to th…

▾ Abyssalsound4 · stream_extensionEPSS 1.6%via NVD
CVE-2022-50696Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.60%via CVEORG
CVE-2022-50694Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username …

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.89%via CVEORG
CVE-2022-50793High· 8.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.1%via CVEORG
CVE-2022-50795High· 7.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a …

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 4.2%via CVEORG
CVE-2022-50791High· 7.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a …

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.8%via CVEORG
CVE-2022-50789High· 7.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malic…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 4.2%via CVEORG
CVE-2023-54327Critical· 9.8
9mo ago

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request

Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially …

▾ Midnighttinycontrol · lan_controller_firmwareEPSS 0.70%via NVD
CVE-2023-54237Critical· 9.8
9mo ago

net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link()

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix potential panic dues to unprotected smc_llc_srv_add_link() There is a certain chance to trigger the following panic: PID: 5900 TASK: ffff88c1c8af4100 …

▾ MidnightLinux · LinuxEPSS 0.56%via CVEORG

Most-affected vendors

By CVEs published in the period.