Weekly digest
Week 19, 2025 (5–11 May)
26 new CVEs this week, in line with the recent average. Of those, 8 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. digitro was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 26 published.
CVE-2025-32873Medium· 5.3PoCDjango has a denial-of-service possibility in strip_tags()
Django has a denial-of-service possibility in strip_tags()
CVE-2025-30165High· 8.0Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
Remote Code Execution Vulnerability in vLLM Multi-Node Cluster Configuration
CVE-2025-1253High· 7.8Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: f…
CVE-2025-1752High· 7.5LlamaIndex Vulnerable to Denial of Service (DoS)
LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-37802High· 7.5ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING"
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix WARNING "do not call blocking ops when !TASK_RUNNING" wait_event_timeout() will set the state of the current task to TASK_UNINTERRUPTIBLE, before doing the …
CVE-2025-1254High· 7.4Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers
Out-of-bounds Read, Out-of-bounds Write vulnerability in RTI Connext Professional (Recording Service) allows Overflow Buffers, Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7,…
CVE-2025-46814High· 7.5FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. A…
FastAPI Guard is a security library for FastAPI that provides middleware to control IPs, log requests, and detect penetration attempts. An HTTP header injection vulnerability has been identified in versions prior to 2.0.0. By manipulatin…
CVE-2025-46726HighLangroid Allows XXE Injection via XMLToolMessage
Langroid Allows XXE Injection via XMLToolMessage
CVE-2025-1252High· 7.1Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags
Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.5.0, from 7.0.0 before 7.3.0.7, from 6.1.0 before 6.1.…
CVE-2025-46730Medium· 6.8Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack
CVE-2025-4374Medium· 6.5A flaw was found in Quay
A flaw was found in Quay. When an organization acts as a proxy cache, and a user or robot pulls an image that hasn't been mirrored yet, they are granted "Admin" permissions on the newly created repository.
CVE-2025-26241Medium· 6.5A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
Most-affected vendors
By CVEs published in the period.