NVD disclosure day

Published threat advisories for December 22, 2025

CVE advisoryCRITICAL

CVE-2025-65856

Xiongmai XM530 Cameras Vulnerable to ONVIF Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A critical authentication bypass vulnerability exists in Xiongmai IP cameras, allowing unauthenticated remote attackers to access sensitive device information and live video streams by exploiting the ONVIF implementation. This could expose surveillance video and camera data.

CVE advisoryCRITICAL

CVE-2025-67418

ClipBucket 5.5.2 Default Admin Credentials Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A hardcoded default credential vulnerability in ClipBucket allows unauthenticated remote attackers to gain full administrative control of the application. This means attackers can potentially access, modify, or delete all application data and alter its behavior without needing any prior authentication or user interacti

CVE advisoryCRITICAL

CVE-2025-67288

Umbraco CMS Arbitrary File Upload Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An arbitrary file upload vulnerability in Umbraco CMS may allow attackers to execute arbitrary code by uploading a crafted PDF. The vendor disputes responsibility, stating file validation is an administrator's duty. This could impact the integrity and availability of the system if not properly secured through configura

CVE advisoryKnown Exploit

CVE-2025-68645

Zimbra Collaboration: File Inclusion Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A Local File Inclusion vulnerability exists in Zimbra Collaboration's Webmail Classic UI. This allows unauthenticated remote attackers to include arbitrary files from the WebRoot directory. This impacts affected organizations by posing a risk of unauthorized data access and potential service disruption. Attackers can e

• CISA KEV

CVE advisoryCRITICAL

CVE-2025-67289

Frappe Framework Arbitrary File Upload Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An arbitrary file upload vulnerability in Frappe Framework's Attachments module enables attackers to execute arbitrary code by uploading a malicious XML file. This vulnerability could impact system data and service behavior if the affected technology is reachable.