Weekly digest
Week 12, 2025 (17–23 Mar)
A heavy week: 113 new CVEs, well above the recent average of about 32. Severity skewed high: 8 critical and 69 high, 68% of the total. 9 arrived with exploitation evidence or public exploit code already attached. CISA added 3 CVEs to the Known Exploited Vulnerabilities catalog. open-webui was the most-affected vendor with 18.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2024-48248High· 8.6CISA KEVPoCNAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /c/router (this may lead to remote code execution across the enterprise because PhysicalDiscovery has cleartext creden…
CVE-2025-30066High· 8.6CISA KEVPoCtj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at comm…
CVE-2025-24472High· 8.1CISA KEVPoCAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…
New this week, ranked by depth score
The 12 that matter most of the 113 published.
CVE-2025-2609High· 8.2PoCImproper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…
CVE-2025-2610High· 7.6PoCImproper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protec…
CVE-2024-9701Critical· 9.8Kedro deserialization vulnerability
Kedro deserialization vulnerability
CVE-2024-9053Critical· 9.8vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
vLLM allows Remote Code Execution by Pickle Deserialization via AsyncEngineRPCServer() RPC server entrypoints
CVE-2024-9052Critical· 9.8vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
vLLM deserialization vulnerability in vllm.distributed.GroupCoordinator.recv_object
CVE-2024-8859High· 7.5PoCMLflow has a Local File Read/Path Traversal in dbfs
MLflow has a Local File Read/Path Traversal in dbfs
CVE-2024-11958Critical· 9.8LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
CVE-2024-11041Critical· 9.8vLLM Deserialization of Untrusted Data vulnerability
vLLM Deserialization of Untrusted Data vulnerability
CVE-2024-12537High· 7.5PoCOpen WebUI Uncontrolled Resource Consumption vulnerability
Open WebUI Uncontrolled Resource Consumption vulnerability
CVE-2024-10829High· 7.5PoCDB-GPT Uncontrolled Resource Consumption vulnerability
DB-GPT Uncontrolled Resource Consumption vulnerability
CVE-2024-10821High· 7.5PoCInvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
InvokeAI has Denial of Service (DoS) vulnerability in `/api/v1/images/upload`
CVE-2024-8769Critical· 9.1Aim path traversal in LockManager.release_locks
Aim path traversal in LockManager.release_locks
Most-affected vendors
By CVEs published in the period.