VulnSea

Weekly digest

Week 18, 2025 (28 Apr – 4 May)

A quiet week: only 17 new CVEs against a recent average of about 44. Of those, 2 critical and 4 high. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 5.

17
New CVEs
2
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 17 published.

CVE-2025-32444Critical· 10.0
1y ago

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

vLLM Vulnerable to Remote Code Execution via Mooncake Integration

▾ Midnightvllm · vllmEPSS 1.7%via OSV
CVE-2022-49770Critical· 9.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprea…

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprea…

▾ Midnightlinux · linux_kernelEPSS 0.56%via NVD
CVE-2025-3501High· 8.2
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

▾ TwilightRed Hat · keycloakEPSS 0.46%via NVD
CVE-2025-3891High· 7.5
1y ago

A flaw was found in the mod_auth_openidc module for Apache httpd

A flaw was found in the mod_auth_openidc module for Apache httpd. This flaw allows a remote, unauthenticated attacker to trigger a denial of service by sending an empty POST request when the OIDCPreservePost directive is enabled. The ser…

▾ Twilightapache · http_serverEPSS 1.6%via NVD
CVE-2025-46569High
1y ago

OPA server Data API HTTP path injection of Rego

OPA server Data API HTTP path injection of Rego

▾ Twilightopen-policy-agent · github.com/open-policy-agent/opa/v1/serverEPSS 0.51%via OSV
CVE-2025-30202High· 7.5
1y ago

Data exposure via ZeroMQ on multi-node vLLM deployment

Data exposure via ZeroMQ on multi-node vLLM deployment

▾ Twilightvllm · vllmEPSS 0.57%via OSV
CVE-2025-46560Medium· 6.5
1y ago

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

phi4mm: Quadratic Time Complexity in Input Token Processing​ leads to denial of service

▾ Sunlitvllm · vllmEPSS 0.50%via OSV
CVE-2025-23160Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp str…

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: Fix a resource leak related to the scp device in FW initialization On Mediatek devices with a system companion processor (SCP) the mtk_scp str…

▾ Sunlitlinux · linux_kernelEPSS 0.20%via NVD
CVE-2022-49833Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: clone zoned device info when cloning a device When cloning a btrfs_device, we're not cloning the associated btrfs_zoned_device_info structure of the devi…

In the Linux kernel, the following vulnerability has been resolved: btrfs: zoned: clone zoned device info when cloning a device When cloning a btrfs_device, we're not cloning the associated btrfs_zoned_device_info structure of the devi…

▾ Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2022-49803Medium· 5.5
1y ago

In the Linux kernel, the following vulnerability has been resolved: netdevsim: Fix memory leak of nsim_dev->fa_cookie kmemleak reports this issue: unreferenced object 0xffff8881bac872d0 (size 8): comm "sh", pid 58603, jiffies 448152…

In the Linux kernel, the following vulnerability has been resolved: netdevsim: Fix memory leak of nsim_dev->fa_cookie kmemleak reports this issue: unreferenced object 0xffff8881bac872d0 (size 8): comm "sh", pid 58603, jiffies 448152…

▾ Sunlitlinux · linux_kernelEPSS 0.19%via NVD
CVE-2025-3910Medium· 5.4
1y ago

A flaw was found in Keycloak

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

▾ Sunlitredhat · build_of_keycloakEPSS 0.44%via NVD
CVE-2025-4032Medium· 5.0
1y ago

AWorld OS Command Injection vulnerability

AWorld OS Command Injection vulnerability

▾ Sunlitaworld · aworldEPSS 3.3%via OSV

Most-affected vendors

By CVEs published in the period.