Weekly digest
Week 6, 2025 (3–9 Feb)
11 new CVEs this week, in line with the recent average. Of those, 4 high. CISA added one CVE to the Known Exploited Vulnerabilities catalog. mobsf was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 11 that matter most of the 11 published.
CVE-2025-24803High· 8.1MobSF Stored Cross-Site Scripting (XSS)
MobSF Stored Cross-Site Scripting (XSS)
CVE-2025-1022High· 8.2Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../…
Versions of the package spatie/browsershot before 5.0.5 are vulnerable to Improper Input Validation in the setHtml function, invoked by Browsershot::html(), which can be bypassed by omitting the slashes in the file URI (e.g., file:../../…
CVE-2025-23217HighMitmweb API Authentication Bypass Using Proxy Server
Mitmweb API Authentication Bypass Using Proxy Server
CVE-2025-24372High· 7.3CKAN has an XSS vector in user uploaded images in group/org and user profiles
CKAN has an XSS vector in user uploaded images in group/org and user profiles
CVE-2025-26260Medium· 6.5Plenti - Code Injection - Denial of Services
Plenti - Code Injection - Denial of Services
CVE-2025-24805Medium· 6.5MobSF Local Privilege Escalation
MobSF Local Privilege Escalation
CVE-2025-24804Medium· 6.5MobSF Partial Denial of Service (DoS)
MobSF Partial Denial of Service (DoS)
CVE-2025-22866Medium· 5.3crypto/internal/nistec: golang: Timing sidechannel for P-256 on ppc64le in crypto/internal/nistec (CVE-2025-22866)
A flaw was found in the Golang crypto/internal/nistec package. Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le archi…
CVE-2025-20205Medium· 4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…
CVE-2025-20204Medium· 4.8Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interf…
CVE-2025-25183Low· 2.6vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
vLLM uses Python 3.12 built-in hash() which leads to predictable hash collisions in prefix cache
Most-affected vendors
By CVEs published in the period.