Weekly digest
Week 8, 2025 (17–23 Feb)
18 new CVEs this week, in line with the recent average. Of those, 4 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-53704Critical· 9.8CISA KEVPoCAn Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication.
CVE-2025-0108Critical· 9.1CISA KEVPoCAn authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…
An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web inter…
New this week, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2025-26465Medium· 6.8PoCA vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error …
CVE-2025-1403High· 8.6Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
Malciously crafted QPY files can allows Remote Attackers to Cause Denial of Service in Qiskit
CVE-2025-21702High· 7.8In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's…
In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's…
CVE-2025-0624High· 7.6A flaw was found in grub2
A flaw was found in grub2. During the network boot process, when trying to search for the configuration file, grub copies data from a user controlled environment variable into an internal buffer using the grub_strcpy() function. During t…
CVE-2025-25305High· 7.0Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
Home Assistant does not correctly validate SSL for outgoing requests in core and used libs
CVE-2024-45777Medium· 6.7A flaw was found in grub2
A flaw was found in grub2. The calculation of the translation buffer when reading a language .mo file in grub_gettext_getstr_from_position() may overflow, leading to a Out-of-bound write. This issue can be leveraged by an attacker to ove…
CVE-2024-45781Medium· 6.7A flaw was found in grub2
A flaw was found in grub2. When reading a symbolic link's name from a UFS filesystem, grub2 fails to validate the string length taken as an input. The lack of validation may lead to a heap out-of-bounds write, causing data integrity issu…
CVE-2024-45776Medium· 6.7When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer
When reading the language .mo file in grub_mofile_open(), grub2 fails to verify an integer overflow when allocating its internal buffer. A crafted .mo file may lead the buffer size calculation to overflow, leading to out-of-bound reads a…
CVE-2024-45774Medium· 6.7A flaw was found in grub2
A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive informatio…
CVE-2024-13461Medium· 6.4The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 du…
The Autoship Cloud for WooCommerce Subscription Products plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'autoship-create-scheduled-order-action' shortcode in all versions up to, and including, 2.8.0 du…
CVE-2025-0677Medium· 6.4A flaw was found in grub2
A flaw was found in grub2. When performing a symlink lookup, the grub's UFS module checks the inode's data size to allocate the internal buffer to read the file content, however, it fails to check if the symlink data size has overflown. …
CVE-2025-0622Medium· 6.4A flaw was found in command/gpg
A flaw was found in command/gpg. In some scenarios, hooks created by loaded modules are not removed when the related module is unloaded. This flaw allows an attacker to force grub2 to call the hooks once the module that registered it was…
Most-affected vendors
By CVEs published in the period.