VulnSea

Daily digest

Tuesday 25 November 2025

6 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 3 high, 67% of the total.

6
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this day, ranked by depth score

The 6 that matter most of the 6 published.

CVE-2025-61168Critical· 9.8
10mo ago

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

▾ Midnightsigb · pmbEPSS 0.49%via NVD
CVE-2025-62703High· 8.8
10mo ago

Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer

Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer

▾ Twilightfugue · fugueEPSS 0.73%via OSV
CVE-2025-65965High
10mo ago

Grype has a credential disclosure vulnerability in its JSON output

Grype has a credential disclosure vulnerability in its JSON output

▾ Twilightanchore · github.com/anchore/grypeEPSS 0.15%via OSV
CVE-2025-13502High· 7.5
10mo ago

A flaw was found in WebKitGTK and WPE WebKit

A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.

▾ TwilightEPSS 0.58%via NVD
CVE-2025-61167Medium· 6.5
10mo ago

SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters.

SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters.

▾ Sunlitsigb · pmbEPSS 0.21%via NVD
CVE-2025-65942Low· 2.7
10mo ago

VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM

VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM

▾ SunlitVictoriaMetrics · github.com/VictoriaMetrics/VictoriaMetricsEPSS 0.34%via OSV

Most-affected vendors

By CVEs published in the period.