VulnSea

Weekly digest

Week 20, 2025 (12–18 May)

21 new CVEs this week, in line with the recent average. Of those, 1 critical and 7 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. siemens was the most-affected vendor with 3.

21
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2025-42999Critical· 9.1CISA KEV
1y ago

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availabili…

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availabili…

▾ Hadalsap · netweaverEPSS 14%via NVD
CVE-2025-27696High· 8.8
1y ago

Apache Superset Allows Ownership Takeover

Apache Superset Allows Ownership Takeover

▾ Twilightapache-superset · apache-supersetEPSS 1.2%via OSV
CVE-2025-47809High· 8.2
1y ago

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot)

Wibu CodeMeter before 8.30a sometimes allows privilege escalation immediately after installation (before a logoff or reboot). For exploitation, there must have been an unprivileged installation with UAC, and the CodeMeter Control Center …

▾ TwilightWibu · CodeMeterEPSS 0.17%via NVD
CVE-2025-31223High· 8.0
1y ago

The issue was addressed with improved checks

The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously crafted web content may lead to memory corruption.

▾ Twilightapple · safariEPSS 0.57%via NVD
CVE-2025-40582High· 7.8
1y ago

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed)

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices do not properly sanitize configuration parameters. This could allo…

▾ Twilightsiemens · scalance_lpe9403_firmwareEPSS 0.18%via NVD
CVE-2025-47287High· 7.5
1y ago

Tornado vulnerable to excessive logging caused by malformed multipart form data

Tornado vulnerable to excessive logging caused by malformed multipart form data

▾ Twilighttornado · tornadoEPSS 0.74%via OSV
CVE-2025-47782High
1y ago

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution

▾ Twilightmotioneye · motioneyeEPSS 0.49%via OSV
CVE-2025-40581High· 7.1
1y ago

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed)

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge Client installed). Affected devices are vulnerable to an authentication bypass. This could allow a non…

▾ Twilightsiemens · scalance_lpe9403_firmwareEPSS 0.15%via NVD
CVE-2025-4478Medium· 6.5
1y ago

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occ…

▾ Sunlitfreerdp · freerdpEPSS 0.52%via NVD
CVE-2025-4476Medium· 4.3PoC
1y ago

A denial-of-service vulnerability has been identified in the libsoup HTTP client library

A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter wit…

▾ TwilightEPSS 0.39%via NVD
CVE-2025-4574Medium· 6.5
1y ago

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.

▾ SunlitEPSS 0.54%via NVD
CVE-2024-28956Medium· 5.6
1y ago

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

▾ SunlitEPSS 0.41%via CVEORG

Most-affected vendors

By CVEs published in the period.