Daily digest
Friday 31 October 2025
8 new CVEs this day, in line with the recent average. Of those, 1 critical and 2 high.
New this day, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2025-6520Critical· 9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection. This issue affects BAPSIS: before 202510271606.
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection. This issue affects BAPSIS: before 202510271606.
CVE-2025-6176High· 7.5Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation
CVE-2025-64168High· 7.1Agno session state overwrites between different sessions/users
Agno session state overwrites between different sessions/users
CVE-2025-63675Medium· 6.9cryptidy allows code execution via untrusted data due to pickle.loads
cryptidy allows code execution via untrusted data due to pickle.loads
CVE-2025-12464Medium· 6.2A stack-based buffer overflow was found in the QEMU e1000 network device
A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped from individual network devices and moved to the net core code. The issue stems from the device's receive code still …
CVE-2025-6075Medium· 5.5If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.
If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding environment variables.
CVE-2024-13992Medium· 5.4Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website
Nagios XI versions prior to < 2024R1.1 is vulnerable to a cross-site scripting (XSS) when a user visits the "missing page" (404) page after following a link from another website. The vulnerable component, page-missing.php, fails to prope…
MAL-2025-191874NoneMalicious code in speed-testing-nt (PyPI)
Malicious code in speed-testing-nt (PyPI)
Most-affected vendors
By CVEs published in the period.