VulnSea

Weekly digest

Week 21, 2025 (19–25 May)

20 new CVEs this week, in line with the recent average. Of those, 3 critical and 6 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 7.

20
New CVEs
3
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2025-47277Critical· 9.8
1y ago

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

vLLM Allows Remote Code Execution via PyNcclPipe Communication Service

▾ Midnightvllm · vllmEPSS 0.96%via OSV
CVE-2025-46724Critical· 9.8
1y ago

Langroid has a Code Injection vulnerability in TableChatAgent

Langroid has a Code Injection vulnerability in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.83%via OSV
CVE-2025-47273HighPoC
1y ago

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

▾ Midnightsetuptools · setuptoolsEPSS 1.5%via OSV
CVE-2025-37959Critical· 9.4
1y ago

bpf: Scrub packet on bpf_redirect_peer

In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device in another network namespace, the skb isn't scrubbed. That can le…

▾ MidnightLinux · LinuxEPSS 0.36%via CVEORG
CVE-2025-37964High· 7.8
1y ago

x86/mm: Eliminate window where TLB flushes may be inadvertently skipped

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window in the mm switching code where the new CR3 is set and the CPU should b…

▾ TwilightLinux · LinuxEPSS 0.19%via CVEORG
CVE-2025-5024High· 7.4
1y ago

A flaw was found in gnome-remote-desktop

A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, …

▾ TwilightEPSS 0.82%via NVD
CVE-2025-46725High
1y ago

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store

▾ Twilightlangroid · langroidEPSS 0.53%via OSV
CVE-2025-37917High· 7.5
1y ago

net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll Use spin_lock_irqsave and spin_unlock_irqrestore instead of spin_lock and spin_unlock in mtk_…

▾ TwilightLinux · LinuxEPSS 0.50%via CVEORG
CVE-2025-4948High· 7.5
1y ago

A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications

A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially cr…

▾ TwilightEPSS 0.78%via NVD
CVE-2025-4969Medium· 6.5
1y ago

A vulnerability was found in the libsoup package

A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing …

▾ SunlitEPSS 0.88%via NVD
CVE-2025-5150Medium· 6.3
1y ago

docarray prototype pollution

docarray prototype pollution

▾ Sunlitdocarray · docarrayEPSS 0.67%via OSV
CVE-2025-5148Medium· 5.3
1y ago

FunAudioLLM InspireMusic deserialization vulnerability

FunAudioLLM InspireMusic deserialization vulnerability

▾ Sunlitinspiremusic · inspiremusicEPSS 0.19%via OSV

Most-affected vendors

By CVEs published in the period.