VulnSea

Daily digest

Monday 5 January 2026

A heavy day: 73 new CVEs, well above the recent average of about 30. Severity skewed high: 10 critical and 33 high, 59% of the total. 3 arrived with exploitation evidence or public exploit code already attached. coollabs was the most-affected vendor with 11.

73
New CVEs
10
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 73 published.

CVE-2025-66376High· 7.2CISA KEV
9mo ago

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

▾ Abyssalsynacor · zimbra_collaboration_suiteEPSS 20%via NVD
CVE-2025-64424High· 8.8PoC
9mo ago

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions up to and including v4.0.0-beta.434, a command injection vulnerability exists in the git source input fields of a res…

▾ Midnightcoollabs · coolifyEPSS 2.1%via NVD
CVE-2025-15029Critical· 9.8
9mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: fro…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Centreon Infra Monitoring (Awie export modules) allows SQL Injection to unauthenticated user. This issue affects Infra Monitoring: fro…

▾ Midnightcentreon · awieEPSS 13%via NVD
CVE-2025-64420Critical· 9.9
9mo ago

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. In Coolify versions prior to and including v4.0.0-beta.434, low privileged users are able to see the private key of the root user on the …

▾ Midnightcoollabs · coolifyEPSS 0.53%via NVD
CVE-2025-59157Critical· 9.9
9mo ago

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection. User input is not…

▾ Midnightcoollabs · coolifyEPSS 1.8%via NVD
CVE-2025-31048Critical· 9.9
9mo ago

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4.

Unrestricted Upload of File with Dangerous Type vulnerability in Themify Shopo allows Upload a Web Shell to a Web Server.This issue affects Shopo: from n/a through 1.1.4.

▾ MidnightEPSS 0.31%via NVD
CVE-2025-68428High· 7.5PoC
9mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to version 4.0.0, user control of the first argument of the loadFile method in the node.js build allows local file inclusion/path traversal. If given the possibility to pass unsani…

▾ Midnightparall · jspdfEPSS 2.2%via NVD
CVE-2025-15026Critical· 9.8
9mo ago

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.…

Missing Authentication for Critical Function vulnerability in Centreon Infra Monitoring centreon-awie (Awie import module) allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Infra Monitoring: from 25.10.…

▾ Midnightcentreon · awieEPSS 0.42%via NVD
CVE-2025-64419Critical· 9.6
9mo ago

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.445, parameters coming from docker-compose.yaml are not sanitized when used in commands. If a victim user cre…

▾ Midnightcoollabs · coolifyEPSS 0.66%via NVD
CVE-2025-68865Critical· 9.3
9mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global: from n/a through <= 2.15.06.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global: from n/a through <= 2.15.06.

▾ MidnightEPSS 0.27%via NVD
CVE-2025-39484Critical· 9.3
9mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.

▾ MidnightEPSS 0.28%via NVD
CVE-2025-30633Critical· 9.3
9mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Native Shopping Recommendations: from n/a…

▾ MidnightEPSS 0.28%via NVD

Most-affected vendors

By CVEs published in the period.