Daily digest
Wednesday 26 November 2025
5 new CVEs this day, in line with the recent average. Severity skewed high: 2 critical and 2 high, 80% of the total. 2 arrived with exploitation evidence or public exploit code already attached.
New this day, ranked by depth score
The 5 that matter most of the 5 published.
CVE-2025-62593High· 8.8CISA KEVPoCRay is an AI compute engine
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…
CVE-2025-50433Critical· 9.8PoCAn issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.
An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.
CVE-2025-64130Critical· 9.8Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.
Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.
CVE-2025-13601High· 7.7A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would ne…
CVE-2021-4472Medium· 6.5OpenStack's Mistral Client has a local file inclusion vulnerability
OpenStack's Mistral Client has a local file inclusion vulnerability
Most-affected vendors
By CVEs published in the period.