Daily digest
Friday 7 November 2025
15 new CVEs this day, in line with the recent average. Severity skewed high: 2 critical and 6 high, 53% of the total. 5 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2025-10230Critical· 10.0PoCA flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserte…
CVE-2025-64495High· 8.7PoCOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
CVE-2025-64512High· 8.6PoCArbitrary Code Execution in pdfminer.six via Crafted PDF Input
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
CVE-2025-70559High· 7.8PoCInsecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
CVE-2025-64338Critical· 9.0ClipBucket v5 is an open source video sharing platform
ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular user can create a photo collection whose Collection Name contains HTML/JavaScript payloads, which making ClipBucket’s Ma…
CVE-2025-64496High· 7.3Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
CVE-2025-64324High· 7.7KubeVirt Vulnerable to Arbitrary Host File Read and Write
KubeVirt Vulnerable to Arbitrary Host File Read and Write
CVE-2025-57698HighAstrBot contains a directory traversal vulnerability
AstrBot contains a directory traversal vulnerability
CVE-2025-64432Medium· 4.7PoCKubeVirt is a virtual machine management add-on for Kubernetes
KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. I…
CVE-2024-47118Medium· 6.5IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certai…
IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to a denial of service as the server may crash under certai…
CVE-2025-57697MediumAstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
CVE-2025-36136Medium· 5.1IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause a denial of service due to the database monitor script incorrectly detecting that the in…
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local user to cause a denial of service due to the database monitor script incorrectly detecting that the in…
Most-affected vendors
By CVEs published in the period.