VulnSea

Daily digest

Thursday 1 January 2026

21 new CVEs this day, in line with the recent average. Severity skewed high: 2 critical and 9 high, 52% of the total. 2 arrived with exploitation evidence or public exploit code already attached. signalk was the most-affected vendor with 6.

21
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2025-66398Critical· 9.6PoC
9mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/validateBackup` endpoi…

▾ Abyssalsignalk · signal_k_serverEPSS 20%via NVD
CVE-2025-68620Critical· 9.1
9mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two features that can be chained together to steal JWT authentication tokens without any prior authentication. The attack combi…

▾ Midnightsignalk · signal_k_serverEPSS 0.54%via NVD
CVE-2025-47411High· 8.1
9mo ago

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.  This vulner…

A user with a legitimate non-administrator account can exploit a vulnerability in the user ID creation mechanism in Apache StreamPipes that allows them to swap the username of an existing user with that of an administrator.  This vulner…

▾ Twilightapache · streampipesEPSS 15%via NVD
CVE-2025-48769High· 8.1
9mo ago

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer realloc…

Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer realloc…

▾ Twilightapache · nuttxEPSS 1.6%via NVD
CVE-2025-11157High· 7.8
9mo ago

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`

A high-severity remote code execution vulnerability exists in feast-dev/feast version 0.53.0, specifically in the Kubernetes materializer job located at `feast/sdk/python/feast/infra/compute_engines/kubernetes/main.py`. The vulnerability…

▾ TwilightEPSS 0.30%via NVD
CVE-2025-68273Medium· 5.3PoC
9mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. An unauthenticated information disclosure vulnerability in versions prior to 2.19.0 allows any user to retrieve sensitive system information, including the ful…

▾ Twilightsignalk · signal_k_serverEPSS 0.82%via NVD
CVE-2025-68272High· 7.5
9mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. A Denial of Service (DoS) vulnerability in versions prior to 2.19.0 allows an unauthenticated attacker to crash the SignalK Server by flooding the access reque…

▾ Twilightsignalk · signal_k_serverEPSS 0.56%via NVD
CVE-2025-68619High· 7.2
9mo ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 of the appstore interface allow administrators to install npm packages through a REST API endpoint. While the endpoint validates that …

▾ Twilightsignalk · signal_k_serverEPSS 0.71%via NVD
CVE-2025-15410High· 7.3
9mo ago

A vulnerability was identified in code-projects Online Guitar Store 1.0

A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument L_email leads to sql injection. It is possible to init…

▾ Twilightanisha · online_guitar_storeEPSS 0.38%via NVD
CVE-2025-15409High· 7.3
9mo ago

A vulnerability was determined in code-projects Online Guitar Store 1.0

A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Delete_product.php. Executing a manipulation of the argument del_pro can lead to sql i…

▾ Twilightanisha · online_guitar_storeEPSS 0.42%via NVD
CVE-2025-15408High· 7.3
9mo ago

A vulnerability was found in code-projects Online Guitar Store 1.0

A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/Create_product.php. Performing a manipulation of the argument dre_title results in sql injection. The attack is possib…

▾ Twilightanisha · online_guitar_storeEPSS 0.38%via NVD
CVE-2025-15407High· 7.3
9mo ago

A vulnerability has been found in code-projects Online Guitar Store 1.0

A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /admin/Create_category.php. Such manipulation of the argument dre_Ctitle leads to sql injection. The attack can be exec…

▾ Twilightanisha · online_guitar_storeEPSS 0.38%via NVD

Most-affected vendors

By CVEs published in the period.