Daily digest
Friday 17 October 2025
A quiet day: only 32 new CVEs against a recent average of about 88. Of those, 5 critical and 3 high. 2 arrived with exploitation evidence or public exploit code already attached. rbi was the most-affected vendor with 10.
New this day, ranked by depth score
The 12 that matter most of the 32 published.
CVE-2025-56218Critical· 9.8PoCAn arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2025-34282Critical· 9.1PoCThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature
ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes th…
CVE-2025-62645Critical· 9.9The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token with administrative privileges for the entire platform via the createToken GraphQL mutation.
CVE-2025-62515Critical· 9.8pyquokka is a framework for making data lakes work for time series
pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class directly uses pickle.loads() to deserialize action bodies received from Flight clients without any sanitization or va…
CVE-2025-11849Critical· 9.3Mammoth is vulnerable to Directory Traversal
Mammoth is vulnerable to Directory Traversal
CVE-2025-48044High· 8.6Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.
CVE-2025-62650High· 8.3The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for use of the diagnostic screen.
CVE-2025-59043High· 7.5OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
CVE-2025-62651Medium· 6.5The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for the bathroom rating interface.
CVE-2025-62508Medium· 6.5Citizen is a MediaWiki skin that makes extensions part of the cohesive experience
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulnerable to stored cross-site scripting in the sticky header button message handling. In stickyHeader.js the copyButtonA…
CVE-2025-62648Medium· 6.4The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.
The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive Thru speaker audio volume.
CVE-2025-62511Medium· 6.3yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content
yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition (CWE-367) in the creation of the default configuratio…
Most-affected vendors
By CVEs published in the period.