VulnSea

Weekly digest

Week 7, 2025 (10–16 Feb)

A busier-than-usual week with 21 new CVEs (recent average about 15). Severity skewed high: 2 critical and 10 high, 57% of the total. 4 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 4.

21
New CVEs
2
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2025-0108Critical· 9.1CISA KEVPoC
1y ago

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…

▾ Hadalpaloaltonetworks · pan-osEPSS 98%via NVD
CVE-2025-24472High· 8.1CISA KEVPoC
1y ago

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…

▾ Abyssalfortinet · fortiproxyEPSS 7.2%via NVD
CVE-2025-21391High· 7.1CISA KEV0day
1y ago

Windows Storage Elevation of Privilege Vulnerability

Windows Storage Elevation of Privilege Vulnerability

▾ Abyssalmicrosoft · windows_10_1507EPSS 2.3%via NVD
CVE-2024-12366Critical· 9.8
1y ago

PandasAI interactive prompt function Remote Code Execution (RCE)

PandasAI interactive prompt function Remote Code Execution (RCE)

▾ Midnightpandasai · pandasaiEPSS 1.2%via OSV
CVE-2025-1244High· 8.8
1y ago

A command injection flaw was found in the text editor Emacs

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execute arbitrary shell commands on a vulnerable system. Exploitation is possible by tricking users into visiting a special…

▾ TwilightEPSS 2.6%via NVD
CVE-2025-25297High· 8.6
1y ago

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

Label Studio allows Server-Side Request Forgery in the S3 Storage Endpoint

▾ Twilightlabel-studio · label-studioEPSS 0.67%via OSV
CVE-2025-25296Medium· 6.1PoC
1y ago

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

Label Studio allows Cross-Site Scripting (XSS) via GET request to `/projects/upload-example` endpoint

▾ Twilightlabel-studio · label-studioEPSS 1.9%via OSV
CVE-2025-1247High· 8.3
1y ago

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope

A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, …

▾ TwilightEPSS 0.79%via NVD
CVE-2025-21701High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and ethnl ops The following trace can be seen if a device is being unregistered while its number of channels are being mo…

In the Linux kernel, the following vulnerability has been resolved: net: avoid race between device unregistration and ethnl ops The following trace can be seen if a device is being unregistered while its number of channels are being mo…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2025-21699High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag Truncate an inode's address space when flipping the GFS2_DIF_JDATA flag: depending on that flag, the pag…

In the Linux kernel, the following vulnerability has been resolved: gfs2: Truncate address space when flipping GFS2_DIF_JDATA flag Truncate an inode's address space when flipping the GFS2_DIF_JDATA flag: depending on that flag, the pag…

▾ Twilightlinux · linux_kernelEPSS 0.25%via NVD
CVE-2025-21697High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Ensure job pointer is set to NULL after job completion After a job completes, the corresponding pointer in the device must be set to NULL

In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Ensure job pointer is set to NULL after job completion After a job completes, the corresponding pointer in the device must be set to NULL. Failing to do so tr…

▾ Twilightlinux · linux_kernelEPSS 0.26%via NVD
CVE-2025-21687High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used…

In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used…

▾ Twilightlinux · linux_kernelEPSS 0.24%via NVD

Most-affected vendors

By CVEs published in the period.