Weekly digest
Week 2, 2025 (6–12 Jan)
16 new CVEs this week, in line with the recent average. Of those, 2 critical and 3 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-41713Critical· 9.1CISA KEVPoCA vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenticated attacker to conduct a path traversal attack, due to insufficient input validation. A succes…
CVE-2025-0282Critical· 9.0CISA KEV0dayPoCA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
CVE-2024-55550Low· 2.7CISA KEVPoCMitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization
Mitel MiCollab through 9.8 SP2 could allow an authenticated attacker with administrative privilege to conduct a local file read, due to insufficient input sanitization. A successful exploit could allow the authenticated admin attacker to…
New this week, ranked by depth score
The 12 that matter most of the 16 published.
CVE-2024-53704Critical· 9.8CISA KEVPoCAn Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
CVE-2025-0282Critical· 9.0CISA KEV0dayPoCA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…
CVE-2023-1907High· 8.0pgAdmin has Incorrect Default Permissions
pgAdmin has Incorrect Default Permissions
CVE-2025-0306High· 7.4A vulnerability was found in Ruby
A vulnerability was found in Ruby. The Ruby interpreter is vulnerable to the Marvin Attack. This attack allows the attacker to decrypt previously encrypted messages or forge signatures by exchanging a large number of messages with the vu…
CVE-2025-21618High· 7.5NiceGUI On Air authentication issue
NiceGUI On Air authentication issue
CVE-2024-13272Medium· 6.3Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.
Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.
CVE-2024-53526Medium· 6.4Composio Command Execution vulnerability
Composio Command Execution vulnerability
CVE-2024-47809Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer dereference when this function is called from request_lock() as lkb->lkb_resou…
In the Linux kernel, the following vulnerability has been resolved: dlm: fix possible lkb_resource null dereference This patch fixes a possible null pointer dereference when this function is called from request_lock() as lkb->lkb_resou…
CVE-2024-55459Mediumkeras Path Traversal vulnerability
keras Path Traversal vulnerability
CVE-2024-53995LowPoCGHSL-2024-288: SickChill open redirect in login
GHSL-2024-288: SickChill open redirect in login
CVE-2025-20033Medium· 4.3Mattermost Improper Validation of Specified Type of Input vulnerability
Mattermost Improper Validation of Specified Type of Input vulnerability
CVE-2025-22151Low· 3.7Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Strawberry GraphQL has type resolution vulnerability in node interface that allows potential data leakage through incorrect type resolution
Most-affected vendors
By CVEs published in the period.