VulnSea

Weekly digest

Week 19, 2025 (5–11 May)

26 new CVEs this week, in line with the recent average. Of those, 8 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. digitro was the most-affected vendor with 3.

26
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 26 published.

CVE-2025-32873Medium· 5.3PoC
1y ago

Django has a denial-of-service possibility in strip_tags()

Django has a denial-of-service possibility in strip_tags()

▾ Twilightdjango · djangoEPSS 14%via OSV
CVE-2025-30165High· 8.0
1y ago

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2025-1253High· 7.8
1y ago

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: f…

▾ Twilightrti · connext_professionalEPSS 0.17%via NVD
CVE-2025-1752High· 7.5
1y ago

LlamaIndex Vulnerable to Denial of Service (DoS)

LlamaIndex Vulnerable to Denial of Service (DoS)

▾ Twilightllama-index · llama-indexEPSS 0.50%via OSV
CVE-2025-37802High· 7.5
1y ago

ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING"

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the …

▾ TwilightLinux · LinuxEPSS 0.34%via CVEORG
CVE-2025-1254High· 7.4
1y ago

Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers

Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7,…

▾ Twilightrti · connext_professionalEPSS 0.24%via NVD
CVE-2025-46814High· 7.5
1y ago

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. A…

FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability has been identified in versions prior to 2.0.0. By manipulatin…

▾ Twilightfastapi-guard · fastapi-guardEPSS 0.32%via OSV
CVE-2025-46726High
1y ago

Langroid Allows XXE Injection via XMLToolMessage

Langroid Allows XXE Injection via XMLToolMessage

▾ Twilightlangroid · langroidEPSS 0.62%via OSV
CVE-2025-1252High· 7.1
1y ago

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.…

▾ Twilightrti · connext_professionalEPSS 0.15%via NVD
CVE-2025-46730Medium· 6.8
1y ago

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

▾ Sunlitmobsf · mobsfEPSS 0.48%via OSV
CVE-2025-4374Medium· 6.5
1y ago

A flaw was found in Quay

A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.

▾ Sunlitredhat · quayEPSS 0.32%via NVD
CVE-2025-26241Medium· 6.5
1y ago

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.

▾ Sunlitenhancesoft · osticketEPSS 0.29%via NVD

Most-affected vendors

By CVEs published in the period.