Daily digest
Tuesday 25 November 2025
6 new CVEs this day, in line with the recent average. Severity skewed high: 1 critical and 3 high, 67% of the total.
New this day, ranked by depth score
The 6 that matter most of the 6 published.
CVE-2025-61168Critical· 9.8An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
CVE-2025-62703High· 8.8Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
CVE-2025-65965HighGrype has a credential disclosure vulnerability in its JSON output
Grype has a credential disclosure vulnerability in its JSON output
CVE-2025-13502High· 7.5A flaw was found in WebKitGTK and WPE WebKit
A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
CVE-2025-61167Medium· 6.5SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters.
SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters.
CVE-2025-65942Low· 2.7VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
Most-affected vendors
By CVEs published in the period.