VulnSea

Weekly digest

Week 16, 2025 (14–20 Apr)

49 new CVEs this week, in line with the recent average. Of those, 4 critical and 19 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 24.

49
New CVEs
4
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 49 published.

CVE-2025-42599Critical· 9.8CISA KEV
1y ago

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution an…

▾ Hadalqualitia · active!_mailEPSS 3.3%via NVD
CVE-2025-32434CriticalPoC
1y ago

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

PyTorch: `torch.load` with `weights_only=True` leads to remote code execution

▾ Abyssaltorch · torchEPSS 2.2%via OSV
CVE-2025-1782Critical· 9.9
1y ago

In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web serv…

In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web serv…

▾ MidnightEPSS 0.54%via NVD
CVE-2025-32911Critical· 9.0
1y ago

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function

A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function. This flaw allows a malicious HTTP client to cause memory corruption in the libsoup server.

▾ MidnightEPSS 0.95%via NVD
CVE-2025-22039High· 8.8
1y ago

ksmbd: fix overflow in dacloffset bounds check

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix overflow in dacloffset bounds check The dacloffset field was originally typed as int and used in an unchecked addition, which could overflow and bypass the …

▾ TwilightLinux · LinuxEPSS 0.78%via CVEORG
CVE-2025-22108High· 8.6
1y ago

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Mask the bd_cnt field in the TX BD properly The bd_cnt field in the TX BD specifies the total number of BDs for the TX packet

In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Mask the bd_cnt field in the TX BD properly The bd_cnt field in the TX BD specifies the total number of BDs for the TX packet. The bd_cnt field has 5 bits an…

▾ Twilightlinux · linux_kernelEPSS 0.36%via NVD
CVE-2025-22121High· 8.4
1y ago

ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()

In the Linux kernel, the following vulnerability has been resolved: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() There's issue as follows: BUG: KASAN: use-after-free in ext4_xattr_inode_dec_ref_all+0x6ff/0x790 Read of …

▾ TwilightLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-3445High· 8.1
1y ago

mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File

mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File

▾ Twilightmholt · github.com/mholt/archiverEPSS 0.50%via OSV
CVE-2025-37785High· 7.8
1y ago

ext4: fix OOB read when checking dotdot dir

In the Linux kernel, the following vulnerability has been resolved: ext4: fix OOB read when checking dotdot dir Mounting a corrupted filesystem with directory which contains '.' dir entry with rec_len == block size results in out-of-bo…

▾ TwilightLinux · LinuxEPSS 0.30%via CVEORG
CVE-2025-22124High· 7.8
1y ago

md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb

In the Linux kernel, the following vulnerability has been resolved: md/md-bitmap: fix wrong bitmap_limit for clustermd when write sb In clustermd, separate write-intent-bitmaps are used for each cluster node: 0 4k …

▾ TwilightLinux · LinuxEPSS 0.20%via CVEORG
CVE-2025-22083High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint If vhost_scsi_set_endpoint is called multiple times without a vhost_scsi_clear_endpoint between t…

In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: Fix handling of multiple calls to vhost_scsi_set_endpoint If vhost_scsi_set_endpoint is called multiple times without a vhost_scsi_clear_endpoint between t…

▾ Twilightlinux · linux_kernelEPSS 0.21%via NVD
CVE-2025-22056High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the parsing logic should place every genev…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the parsing logic should place every genev…

▾ Twilightlinux · linux_kernelEPSS 0.32%via NVD

Most-affected vendors

By CVEs published in the period.