VulnSea

Weekly digest

Week 4, 2025 (20–26 Jan)

13 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 6 high, 62% of the total. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 5.

13
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 13 published.

CVE-2025-23006Critical· 9.8CISA KEV0day
1y ago

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…

▾ Hadalsonicwall · sma8200vEPSS 23%via NVD
CVE-2025-21663Critical· 10.0
1y ago

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require the IOMMU "Stream ID" (SID) to be written to the MGBE_WRAP_AXI_…

In the Linux kernel, the following vulnerability has been resolved: net: stmmac: dwmac-tegra: Read iommu stream id from device tree Nvidia's Tegra MGBE controllers require the IOMMU "Stream ID" (SID) to be written to the MGBE_WRAP_AXI_…

▾ Midnightlinux · linux_kernelEPSS 0.41%via NVD
CVE-2024-11218High· 8.6
1y ago

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile

A vulnerability was found in `podman build` and `buildah.` This issue occurs in a container breakout by using --jobs=2 and a race condition when building a malicious Containerfile. SELinux might mitigate it, but even with SELinux on, it …

▾ Twilightcontainers · github.com/containers/buildahEPSS 0.36%via NVD
CVE-2025-24359High· 8.4
1y ago

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

ASTEVAL Allows Maliciously Crafted Format Strings to Lead to Sandbox Escape

▾ Twilightasteval · astevalEPSS 0.28%via OSV
CVE-2025-21659High· 8.1
1y ago

In the Linux kernel, the following vulnerability has been resolved: netdev: prevent accessing NAPI instances from another namespace The NAPI IDs were not fully exposed to user space prior to the netlink API, so they were never namespac…

In the Linux kernel, the following vulnerability has been resolved: netdev: prevent accessing NAPI instances from another namespace The NAPI IDs were not fully exposed to user space prior to the netlink API, so they were never namespac…

▾ Twilightlinux · linux_kernelEPSS 0.18%via NVD
CVE-2025-22153High· 7.9
1y ago

try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter

try/except* clauses could allow bypass RestrictedPython via type confusion bug in the CPython interpreter

▾ Twilightrestrictedpython · restrictedpythonEPSS 0.40%via OSV
CVE-2025-21664High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: dm thin: make get_first_thin use rcu-safe list first function The documentation in rculist.h explains the absence of list_empty_rcu() and cautions programmers against …

In the Linux kernel, the following vulnerability has been resolved: dm thin: make get_first_thin use rcu-safe list first function The documentation in rculist.h explains the absence of list_empty_rcu() and cautions programmers against …

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2025-21661High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix missing lookup table cleanups When a virtuser device is created via configfs and the probe fails due to an incorrect lookup table, the table is not…

In the Linux kernel, the following vulnerability has been resolved: gpio: virtuser: fix missing lookup table cleanups When a virtuser device is created via configfs and the probe fails due to an incorrect lookup table, the table is not…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2024-22347Medium· 5.9
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

▾ Sunlithcltech · devops_velocityEPSS 0.33%via NVD
CVE-2025-0604Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are ex…

▾ SunlitRed Hat · keycloak-ldap-federationEPSS 0.59%via NVD
CVE-2024-22348Medium· 5.3
1y ago

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0

IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is n…

▾ Sunlithcltech · devops_velocityEPSS 0.36%via NVD
CVE-2025-21655Medium· 4.7
1y ago

In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the i…

In the Linux kernel, the following vulnerability has been resolved: io_uring/eventfd: ensure io_eventfd_signal() defers another RCU period io_eventfd_do_signal() is invoked from an RCU callback, but when dropping the reference to the i…

▾ Sunlitlinux · linux_kernelEPSS 0.25%via NVD

Most-affected vendors

By CVEs published in the period.