VulnSea

Weekly digest

Week 5, 2025 (27 Jan – 2 Feb)

16 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 7 high, 50% of the total. No new KEV entries. linux was the most-affected vendor with 6.

16
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 16 published.

CVE-2025-21673Critical· 9.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS t…

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double free of TCP_Server_Info::hostname When shutting down the server in cifs_put_tcp_session(), cifsd thread might be reconnecting to multiple DFS t…

▾ Midnightlinux · linux_kernelEPSS 0.41%via NVD
CVE-2024-13484High· 8.2
1y ago

A flaw was found in openshift-gitops-operator-container

A flaw was found in openshift-gitops-operator-container. The openshift.io/cluster-monitoring label is applied to all namespaces that deploy an ArgoCD CR instance, allowing the namespace to create a rogue PrometheusRule. This issue can ha…

▾ TwilightEPSS 0.22%via NVD
CVE-2025-21678High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a list in dev_net(dev) instead of src_net, where a udp tunnel socket is …

In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a list in dev_net(dev) instead of src_net, where a udp tunnel socket is …

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD
CVE-2025-21677High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket's netns dismantle. pfcp_newlink() links the device to a list in dev_net(dev) instead of net, where a udp tunnel socket is cr…

In the Linux kernel, the following vulnerability has been resolved: pfcp: Destroy device along with udp socket's netns dismantle. pfcp_newlink() links the device to a list in dev_net(dev) instead of net, where a udp tunnel socket is cr…

▾ Twilightlinux · linux_kernelEPSS 0.19%via NVD
CVE-2025-21669High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned to another transport, we must discard any packets received becaus…

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned to another transport, we must discard any packets received becaus…

▾ Twilightlinux · linux_kernelEPSS 0.23%via NVD
CVE-2025-24357High· 7.5
1y ago

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

vllm: Malicious model to RCE by torch.load in hf_model_weights_iterator

▾ Twilightvllm · vllmEPSS 0.70%via OSV
CVE-2025-24793High· 7.0
1y ago

snowflake-connector-python vulnerable to SQL Injection in write_pandas

snowflake-connector-python vulnerable to SQL Injection in write_pandas

▾ Twilightsnowflake-connector-python · snowflake-connector-pythonEPSS 0.31%via OSV
CVE-2024-45339High· 7.1
1y ago

Insecure Temporary File usage in github.com/golang/glog

Insecure Temporary File usage in github.com/golang/glog

▾ Twilightgolang · github.com/golang/glogEPSS 0.32%via OSV
GHSA-274v-mgcv-cm8jMedium· 6.8
1y ago

Argo CD GitOps Engine does not scrub secret values from patch errors

Argo CD GitOps Engine does not scrub secret values from patch errors

▾ Sunlitargoproj · github.com/argoproj/gitops-enginevia OSV
CVE-2025-23216Medium· 6.8
1y ago

Argo CD does not scrub secret values from patch errors

Argo CD does not scrub secret values from patch errors

▾ Sunlitargoproj · github.com/argoproj/argo-cd/v2EPSS 0.47%via OSV
CVE-2025-24794Medium· 6.7
1y ago

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

snowflake-connector-python vulnerable to insecure deserialization of the OCSP response cache

▾ Sunlitsnowflake-connector-python · snowflake-connector-pythonEPSS 0.25%via OSV
CVE-2025-23367Medium· 6.5
1y ago

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider

A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can sus…

▾ Sunlitredhat · jboss_enterprise_application_platformEPSS 0.77%via NVD

Most-affected vendors

By CVEs published in the period.