VulnSea

Weekly digest

Week 8, 2025 (17–23 Feb)

18 new CVEs this week, in line with the recent average. Of those, 4 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

18
New CVEs
0
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2025-26465Medium· 6.8PoC
1y ago

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled

A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error …

▾ Twilightopenbsd · opensshEPSS 7.7%via NVD
CVE-2025-1403High· 8.6
1y ago

Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit

Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit

▾ Twilightqiskit · qiskitEPSS 0.72%via OSV
CVE-2025-21702High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's…

In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's…

▾ Twilightlinux · linux_kernelEPSS 0.27%via NVD
CVE-2025-0624High· 7.6
1y ago

A flaw was found in grub2

A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During t…

▾ TwilightEPSS 1.4%via NVD
CVE-2025-25305High· 7.0
1y ago

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

Home Assistant does not correctly validate SSL for outgoing requests in core and used libs

▾ Twilighthomeassistant · homeassistantEPSS 0.25%via OSV
CVE-2024-45777Medium· 6.7
1y ago

A flaw was found in grub2

A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to ove…

▾ Sunlitgnu · grub2EPSS 0.24%via NVD
CVE-2024-45781Medium· 6.7
1y ago

A flaw was found in grub2

A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issu…

▾ SunlitEPSS 0.26%via NVD
CVE-2024-45776Medium· 6.7
1y ago

When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer

When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads a…

▾ SunlitEPSS 0.26%via NVD
CVE-2024-45774Medium· 6.7
1y ago

A flaw was found in grub2

A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive informatio…

▾ SunlitEPSS 0.27%via NVD
CVE-2024-13461Medium· 6.4
1y ago

The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 du…

The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 du…

▾ Sunlitpatternsinthecloud · autoship_cloud_for_woocommerceEPSS 0.25%via NVD
CVE-2025-0677Medium· 6.4
1y ago

A flaw was found in grub2

A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. …

▾ SunlitEPSS 0.33%via NVD
CVE-2025-0622Medium· 6.4
1y ago

A flaw was found in command/gpg

A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was…

▾ SunlitEPSS 0.28%via NVD

Most-affected vendors

By CVEs published in the period.