Weekly digest
Week 17, 2025 (21–27 Apr)
A quiet week: only 24 new CVEs against a recent average of about 56. Of those, 4 critical and 4 high. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. fig2dev_project was the most-affected vendor with 4.
New this week, ranked by depth score
The 12 that matter most of the 24 published.
CVE-2025-32432Critical· 10.0CISA KEVPoCCraft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to r…
CVE-2025-31324Critical· 10.0CISA KEVPoCSAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could signifi…
GHSA-ggpf-24jw-3fcwCritical· 9.8CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-24357 Malicious model remote code execution fix bypass with PyTorch < 2.6.0
CVE-2025-43859Critical· 9.1h11 accepts some malformed Chunked-Encoding bodies
h11 accepts some malformed Chunked-Encoding bodies
CVE-2025-43971High· 8.6GoBGP panics due to a zero value for softwareVersionLen
GoBGP panics due to a zero value for softwareVersionLen
CVE-2025-46397High· 7.8A flaw was found in xfig
A flaw was found in xfig. This vulnerability allows possible code execution via local input manipulation via bezier_spline function.
CVE-2025-46252High· 7.6Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a thr…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kofi Mokome Message Filter for Contact Form 7 allows SQL Injection. This issue affects Message Filter for Contact Form 7: from n/a thr…
CVE-2025-3511High· 7.5Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link…
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric Corporation CC-Link IE TSN Remote I/O module, CC-Link IE TSN Analog-Digital Converter module, CC-Link IE TSN Digital-Analog Converter module, CC-Link…
CVE-2025-46421Medium· 6.8A flaw was found in libsoup
A flaw was found in libsoup. When libsoup clients encounter an HTTP redirect, they mistakenly send the HTTP Authorization header to the new host that the redirection points to. This allows the new host to impersonate the user to the orig…
CVE-2025-46599Medium· 6.8CNCF K3s Kubernetes kubelet configuration exposes credentials
CNCF K3s Kubernetes kubelet configuration exposes credentials
CVE-2025-46420Medium· 6.5A flaw was found in libsoup
A flaw was found in libsoup. It is vulnerable to memory leaks in the soup_header_parse_quality_list() function when parsing a quality list that contains elements with all zeroes.
CVE-2025-41395Medium· 6.5Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Most-affected vendors
By CVEs published in the period.