VulnSea

Weekly digest

Week 17, 2025 (21–27 Apr)

A quiet week: only 24 new CVEs against a recent average of about 56. Of those, 4 critical and 4 high. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. fig2dev_project was the most-affected vendor with 4.

24
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 24 published.

CVE-2025-32432Critical· 10.0CISA KEVPoC
1y ago

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to r…

▾ Hadalcraftcms · craft_cmsEPSS 100%via NVD
CVE-2025-31324Critical· 10.0CISA KEVPoC
1y ago

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could signifi…

▾ Hadalsap · netweaverEPSS 99%via NVD
GHSA-ggpf-24jw-3fcwCritical· 9.8
1y ago

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0

▾ Midnightvllm · vllmvia OSV
CVE-2025-43859Critical· 9.1
1y ago

h11 accepts some malformed Chunked-Encoding bodies

h11 accepts some malformed Chunked-Encoding bodies

▾ Midnighth11 · h11EPSS 0.58%via OSV
CVE-2025-43971High· 8.6
1y ago

GoBGP panics due to a zero value for softwareVersionLen

GoBGP panics due to a zero value for softwareVersionLen

▾ Twilightosrg · github.com/osrg/gobgp/v3EPSS 0.55%via OSV
CVE-2025-46397High· 7.8
1y ago

A flaw was found in xfig

A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.

▾ Twilightfig2dev_project · fig2devEPSS 0.30%via NVD
CVE-2025-46252High· 7.6
1y ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a thr…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a thr…

▾ Twilightkofimokome · message_filter_for_contact_form_7EPSS 0.39%via NVD
CVE-2025-3511High· 7.5
1y ago

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link…

Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link…

▾ TwilightEPSS 0.91%via NVD
CVE-2025-46421Medium· 6.8
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the orig…

▾ SunlitEPSS 0.57%via NVD
CVE-2025-46599Medium· 6.8
1y ago

CNCF K3s Kubernetes kubelet configuration exposes credentials

CNCF K3s Kubernetes kubelet configuration exposes credentials

▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.45%via OSV
CVE-2025-46420Medium· 6.5
1y ago

A flaw was found in libsoup

A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.

▾ SunlitEPSS 0.58%via NVD
CVE-2025-41395Medium· 6.5
1y ago

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

▾ Sunlitmattermost · github.com/mattermost/mattermost-plugin-playbooksEPSS 0.49%via OSV

Most-affected vendors

By CVEs published in the period.