Daily digest
Tuesday 18 November 2025
A busier-than-usual day with 15 new CVEs (recent average about 12). Of those, 2 critical and 4 high. 3 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 12 that matter most of the 15 published.
CVE-2025-48593High· 8.0PoCIn bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free
In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed…
CVE-2025-65015Criticaljoserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads
CVE-2025-60455CriticalModular Max Serve has Unsafe Deserialization vulnerability
Modular Max Serve has Unsafe Deserialization vulnerability
CVE-2025-63892Medium· 6.8PoCA vulnerability was determined in SourceCodester Student Grades Management System 1.0
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument…
CVE-2025-56499Medium· 6.5PoCIncorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.
Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.
CVE-2025-61662High· 7.8A Use-After-Free vulnerability has been discovered in GRUB's gettext module
A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condi…
CVE-2025-64076High· 7.5Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (s…
Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read (CWE-191, CWE-125): An incorre…
CVE-2025-55796High· 7.5The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email change confirmation
The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflows such as signup confirmation, password resets, email confirmation resends, and email change confirmation. These toke…
CVE-2025-61664Medium· 4.9A vulnerability in the GRUB2 bootloader has been identified in the normal module
A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free issue, occurs because the normal_exit command is not properly unregistered when its related module is unloaded. An attac…
CVE-2025-61663Medium· 4.9A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk
A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the normal command is not properly unregistered when t…
CVE-2025-54771Medium· 4.9A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader)
A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because the file-closing process incorrectly retains a memory pointer, leaving an invalid reference to a file system structure…
CVE-2025-54770Medium· 4.9A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk
A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (DoS) risk. This flaw is a Use-after-Free issue, caused because the net_set_vlan command is not properly unregistered …
Most-affected vendors
By CVEs published in the period.