VulnSea

Weekly digest

Week 51, 2025 (15–21 Dec)

A busier-than-usual week with 49 new CVEs (recent average about 38). Of those, 3 critical and 18 high. 5 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 6.

49
New CVEs
3
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 49 published.

CVE-2025-14733Critical· 9.8CISA KEV0dayPoC
9mo ago

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…

Hadalwatchguard · firewareEPSS 27%via NVD
CVE-2025-43529High· 8.8CISA KEV0dayPoC
9mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malici…

AbyssalApple · SafariEPSS 8.8%via CVEORG
CVE-2025-65318Critical· 9.1PoC
9mo ago

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS…

Abyssalcanarymail · canary_mailEPSS 0.56%via NVD
CVE-2025-63389Critical
9mo ago

Ollama Platform has missing authentication enabling attackers to perform model management operations

Ollama Platform has missing authentication enabling attackers to perform model management operations

Midnightollama · github.com/ollama/ollamaEPSS 0.71%via OSV
CVE-2025-46281High· 8.8
9mo ago

A logic issue was addressed with improved checks

A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An app may be able to break out of its sandbox.

Twilightapple · macosEPSS 0.20%via NVD
CVE-2025-65427Medium· 6.5PoC
9mo ago

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

An issue was discovered in Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router on firmware version V1.0.0 does not implement rate limiting to /api/login allowing attackers to brute force password enumerations.

Twilightdbitnet · dbit_n300_t1_pro_firmwareEPSS 0.27%via NVD
CVE-2025-11393High· 8.7
9mo ago

A flaw was found in runtimes-inventory-rhel8-operator

A flaw was found in runtimes-inventory-rhel8-operator. An internal proxy component is incorrectly configured. Because of this flaw, the proxy attaches the cluster's main administrative credentials to any command it receives, instead of o…

TwilightEPSS 0.20%via NVD
CVE-2025-34469High· 8.3
9mo ago

Cowrie has a SSRF vulnerability in wget/curl emulation enabling DDoS amplification

Cowrie has a SSRF vulnerability in wget/curl emulation enabling DDoS amplification

Twilightcowrie · cowrieEPSS 0.69%via OSV
CVE-2025-14300High· 8.1
9mo ago

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication

The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5  exposes a connectAP interface without proper authentication. An unauthenticated attacker on the same local network segment can exploit this to modify the device’s Wi-Fi config…

Twilighttp-link · tapo_c200_firmwareEPSS 0.37%via NVD
CVE-2025-68477High· 7.7
9mo ago

Langflow vulnerable to Server-Side Request Forgery

Langflow vulnerable to Server-Side Request Forgery

Twilightlangflow · langflowEPSS 6.3%via OSV
CVE-2025-46291High· 7.8
9mo ago

A logic issue was addressed with improved validation

A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass Gatekeeper checks.

Twilightapple · macosEPSS 0.20%via NVD
CVE-2025-68265High· 7.8
9mo ago

nvme: fix admin request_queue lifetime

In the Linux kernel, the following vulnerability has been resolved: nvme: fix admin request_queue lifetime The namespaces can access the controller's admin request_queue, and stale references on the namespaces may exist after tearing d…

TwilightLinux · LinuxEPSS 0.15%via CVEORG

Most-affected vendors

By CVEs published in the period.