Daily digest
Wednesday 5 November 2025
A quiet day: only 5 new CVEs against a recent average of about 16. Severity skewed high: 3 high, 60% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 5 that matter most of the 5 published.
CVE-2023-43000High· 8.8CISA KEVPoCA use-after-free issue was addressed with improved memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to …
CVE-2025-64458High· 7.5PoCDjango has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-64439HighLangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer
CVE-2025-58337MediumApache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
Apache Doris-MCP-Server: Improper Access Control results in bypassing a "read-only" mode
CVE-2025-43418Medium· 4.6This issue was addressed by restricting options offered on a locked device
This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1. An attacker with physical access to a locked device may be able to view sensitive …
Most-affected vendors
By CVEs published in the period.