VulnSea

Weekly digest

Week 6, 2025 (3–9 Feb)

11 new CVEs this week, in line with the recent average. Of those, 4 high. CISA added one CVE to the Known Exploited Vulnerabilities catalog. mobsf was the most-affected vendor with 3.

11
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 11 that matter most of the 11 published.

CVE-2025-24803High· 8.1
1y ago

MobSF Stored Cross-Site Scripting (XSS)

MobSF Stored Cross-Site Scripting (XSS)

▾ Twilightmobsf · mobsfEPSS 0.39%via OSV
CVE-2025-1022High· 8.2
1y ago

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../…

Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../…

▾ TwilightEPSS 0.46%via NVD
CVE-2025-23217High
1y ago

Mitmweb API Authentication Bypass Using Proxy Server

Mitmweb API Authentication Bypass Using Proxy Server

▾ Twilightmitmproxy · mitmproxyEPSS 0.83%via OSV
CVE-2025-24372High· 7.3
1y ago

CKAN has an XSS vector in user uploaded images in group/org and user profiles

CKAN has an XSS vector in user uploaded images in group/org and user profiles

▾ Twilightckan · ckanEPSS 0.46%via OSV
CVE-2025-26260Medium· 6.5
1y ago

Plenti - Code Injection - Denial of Services

Plenti - Code Injection - Denial of Services

▾ Sunlitplentico · github.com/plentico/plentiEPSS 0.76%via OSV
CVE-2025-24805Medium· 6.5
1y ago

MobSF Local Privilege Escalation

MobSF Local Privilege Escalation

▾ Sunlitmobsf · mobsfEPSS 0.36%via OSV
CVE-2025-24804Medium· 6.5
1y ago

MobSF Partial Denial of Service (DoS)

MobSF Partial Denial of Service (DoS)

▾ Sunlitmobsf · mobsfEPSS 0.46%via OSV
CVE-2025-22866Medium· 5.3
1y ago

crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)

A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le archi…

▾ SunlitRed Hat · Red Hat Enterprise Linux AppStream E4S (v.8.8)EPSS 0.29%via CSAF
CVE-2025-20205Medium· 4.8
1y ago

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

▾ Sunlitcisco · identity_services_engineEPSS 0.33%via NVD
CVE-2025-20204Medium· 4.8
1y ago

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…

▾ Sunlitcisco · identity_services_engineEPSS 0.33%via NVD
CVE-2025-25183Low· 2.6
1y ago

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache

▾ Sunlitvllm · vllmEPSS 0.19%via OSV

Most-affected vendors

By CVEs published in the period.