VulnSea

Weekly digest

Week 9, 2025 (24 Feb – 2 Mar)

A heavy week: 118 new CVEs, well above the recent average of about 18. Of those, 3 critical and 54 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 102.

118
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 118 published.

CVE-2025-25279Critical· 9.9PoC
1y ago

Mattermost allows reading arbitrary files related to importing boards

Mattermost allows reading arbitrary files related to importing boards

▾ Abyssalmattermost · github.com/mattermost/mattermost/server/v8EPSS 24%via OSV
CVE-2025-21805Critical· 9.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the rnbd: list_add corruption

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Add missing deinit() call A warning is triggered when repeatedly connecting and disconnecting the rnbd: list_add corruption. prev->next should be next (fff…

▾ Midnightlinux · linux_kernelEPSS 0.39%via NVD
CVE-2025-21748Critical· 9.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add b…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add b…

▾ Midnightlinux · linux_kernelEPSS 0.61%via NVD
CVE-2025-26466Medium· 5.9PoC
1y ago

A flaw was found in the OpenSSH package

A flaw was found in the OpenSSH package. For each ping packet the SSH server receives, a pong packet is allocated in a memory buffer and stored in a queue of packages. It is only freed when the server/client key exchange has finished. A …

▾ Twilightopenbsd · opensshEPSS 40%via NVD
CVE-2025-21760High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_…

In the Linux kernel, the following vulnerability has been resolved: ndisc: extend RCU protection in ndisc_send_skb() ndisc_send_skb() can be called without RTNL or RCU held. Acquire rcu_read_lock() earlier, so that we can use dev_net_…

▾ Twilightlinux · linux_kernelEPSS 37%via NVD
CVE-2025-21735High· 8.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corr…

▾ Twilightlinux · linux_kernelEPSS 0.38%via NVD
CVE-2022-49519High· 8.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: ath10k: skip ath10k_halt during suspend for driver state RESTARTING Double free crash is observed when FW recovery(caused by wmi timeout/crash) is followed by immediat…

In the Linux kernel, the following vulnerability has been resolved: ath10k: skip ath10k_halt during suspend for driver state RESTARTING Double free crash is observed when FW recovery(caused by wmi timeout/crash) is followed by immediat…

▾ Twilightlinux · linux_kernelEPSS 0.35%via NVD
CVE-2022-49328High· 8.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: mt76: fix use-after-free by removing a non-RCU wcid pointer Fixes an issue caught by KASAN about use-after-free in mt76_txq_schedule by protecting mtxq->wcid with rcu_…

In the Linux kernel, the following vulnerability has been resolved: mt76: fix use-after-free by removing a non-RCU wcid pointer Fixes an issue caught by KASAN about use-after-free in mt76_txq_schedule by protecting mtxq->wcid with rcu_…

▾ Twilightlinux · linux_kernelEPSS 0.42%via NVD
CVE-2022-49159High· 8.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Implement ref count for SRB The timeout handler and the done function are racing

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Implement ref count for SRB The timeout handler and the done function are racing. When qla2x00_async_iocb_timeout() starts to run it can be preempted by…

▾ Twilightlinux · linux_kernelEPSS 0.33%via NVD
CVE-2025-0690Medium· 6.1PoC
1y ago

The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character

The read command is used to read the keyboard input from the user, while reads it keeps the input length in a 32-bit integer value which is further used to reallocate the line buffer to accept the next character. During this process, wit…

▾ TwilightEPSS 0.72%via NVD
CVE-2025-21766High· 8.1
1y ago

In the Linux kernel, the following vulnerability has been resolved: ipv4: use RCU protection in __ip_rt_update_pmtu() __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear.

In the Linux kernel, the following vulnerability has been resolved: ipv4: use RCU protection in __ip_rt_update_pmtu() __ip_rt_update_pmtu() must use RCU protection to make sure the net structure it reads does not disappear.

▾ Twilightlinux · linux_kernelEPSS 0.54%via NVD
CVE-2025-21762High· 8.1
1y ago

In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.

In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.

▾ Twilightlinux · linux_kernelEPSS 0.64%via NVD

Most-affected vendors

By CVEs published in the period.