Weekly digest
Week 18, 2025 (28 Apr – 4 May)
A quiet week: only 17 new CVEs against a recent average of about 44. Of those, 2 critical and 4 high. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2025-31324Critical· 10.0CISA KEVPoCSAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could signifi…
CVE-2025-42599Critical· 9.8CISA KEVActive! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution an…
New this week, ranked by depth score
The 12 that matter most of the 17 published.
CVE-2025-32444Critical· 10.0vLLM Vulnerable to Remote Code Execution via Mooncake Integration
vLLM Vulnerable to Remote Code Execution via Mooncake Integration
CVE-2022-49770Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprea…
In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprea…
CVE-2025-3501High· 8.2A flaw was found in Keycloak
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
CVE-2025-3891High· 7.5A flaw was found in the mod_auth_openidc module for Apache httpd
A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The ser…
CVE-2025-46569HighOPA server Data API HTTP path injection of Rego
OPA server Data API HTTP path injection of Rego
CVE-2025-30202High· 7.5Data exposure via ZeroMQ on multi-node vLLM deployment
Data exposure via ZeroMQ on multi-node vLLM deployment
CVE-2025-46560Medium· 6.5phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
phi4mm: Quadratic Time Complexity in Input Token Processing leads to denial of service
CVE-2025-23160Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp str…
In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp str…
CVE-2022-49833Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: clone zoned device info when cloning a device When cloning a btrfs_device, we're not cloning the associated btrfs_zoned_device_info structure of the devi…
In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: clone zoned device info when cloning a device When cloning a btrfs_device, we're not cloning the associated btrfs_zoned_device_info structure of the devi…
CVE-2022-49803Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: netdevsim: Fix memory leak of nsim_dev->fa_cookie kmemleak reports this issue: unreferenced object 0xffff8881bac872d0 (size 8): comm "sh", pid 58603, jiffies 448152…
In the Linux kernel, the following vulnerability has been resolved: netdevsim: Fix memory leak of nsim_dev->fa_cookie kmemleak reports this issue: unreferenced object 0xffff8881bac872d0 (size 8): comm "sh", pid 58603, jiffies 448152…
CVE-2025-3910Medium· 5.4A flaw was found in Keycloak
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
CVE-2025-4032Medium· 5.0AWorld OS Command Injection vulnerability
AWorld OS Command Injection vulnerability
Most-affected vendors
By CVEs published in the period.