VulnSea

Daily digest

Thursday 8 January 2026

A heavy day: 83 new CVEs, well above the recent average of about 50. Severity skewed high: 10 critical and 43 high, 64% of the total. 4 arrived with exploitation evidence or public exploit code already attached. haxx was the most-affected vendor with 6.

83
New CVEs
10
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 12 that matter most of the 83 published.

CVE-2025-59470Critical· 9.0PoC
8mo ago

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

▾ Abyssalveeam · veeam_backup_&_replicationEPSS 1.6%via NVD
CVE-2025-69258Critical· 9.8
8mo ago

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM…

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM…

▾ Midnighttrendmicro · apex_centralEPSS 3.6%via NVD
CVE-2025-67924Critical· 9.9
8mo ago

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affects Corpkit: from n/a through <= 2.0.

Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to a Web Server.This issue affects Corpkit: from n/a through <= 2.0.

▾ MidnightEPSS 0.38%via NVD
CVE-2025-67911Critical· 9.8
8mo ago

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.

▾ MidnightEPSS 0.45%via NVD
CVE-2025-62877Critical· 9.8
8mo ago

Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluste…

Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are using the 1.5.x or 1.6.x interactive installer to either create a new cluster or add new hosts to an existing cluste…

▾ MidnightEPSS 0.52%via NVD
CVE-2025-23504Critical· 9.8
8mo ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through <= 1.1.3.

Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allows Authentication Abuse.This issue affects Felan Framework: from n/a through <= 1.1.3.

▾ MidnightEPSS 0.50%via NVD
CVE-2025-65518High· 7.5PoC
8mo ago

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition

Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability exists in the get_password.php endpoint, where a crafted request containing a malicious payload can cause the affected…

▾ Midnightwebpros · plesk_obsidianEPSS 0.62%via NVD
CVE-2025-67928Critical· 9.3
8mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows Blind SQL Injection.This issue affects Automotive Listings: from n/a through <= 18.6.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automotive Listings automotive allows Blind SQL Injection.This issue affects Automotive Listings: from n/a through <= 18.6.

▾ MidnightEPSS 0.33%via NVD
CVE-2025-23993Critical· 9.3
8mo ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through <= 1.1.3.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Framework felan-framework allows SQL Injection.This issue affects Felan Framework: from n/a through <= 1.1.3.

▾ MidnightEPSS 0.40%via NVD
CVE-2025-59469Critical· 9.0
8mo ago

This vulnerability allows a Backup or Tape Operator to write files as root.

This vulnerability allows a Backup or Tape Operator to write files as root.

▾ Midnightveeam · veeam_backup_&_replicationEPSS 0.64%via NVD
CVE-2025-59468Critical· 9.0
8mo ago

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

▾ Midnightveeam · veeam_backup_&_replicationEPSS 1.2%via NVD
CVE-2025-67915High· 8.8
8mo ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46.

Authentication Bypass Using an Alternate Path or Channel vulnerability in Arraytics Timetics timetics allows Authentication Abuse.This issue affects Timetics: from n/a through <= 1.0.46.

▾ TwilightEPSS 0.43%via NVD

Most-affected vendors

By CVEs published in the period.