Weekly digest
Week 21, 2025 (19–25 May)
20 new CVEs this week, in line with the recent average. Of those, 3 critical and 6 high. 2 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 7.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 20 published.
CVE-2025-47277Critical· 9.8vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
vLLM Allows Remote Code Execution via PyNcclPipe Communication Service
CVE-2025-46724Critical· 9.8Langroid has a Code Injection vulnerability in TableChatAgent
Langroid has a Code Injection vulnerability in TableChatAgent
CVE-2025-47273HighPoCsetuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write
CVE-2025-37959Critical· 9.4bpf: Scrub packet on bpf_redirect_peer
In the Linux kernel, the following vulnerability has been resolved: bpf: Scrub packet on bpf_redirect_peer When bpf_redirect_peer is used to redirect packets to a device in another network namespace, the skb isn't scrubbed. That can le…
CVE-2025-37964High· 7.8x86/mm: Eliminate window where TLB flushes may be inadvertently skipped
In the Linux kernel, the following vulnerability has been resolved: x86/mm: Eliminate window where TLB flushes may be inadvertently skipped tl;dr: There is a window in the mm switching code where the new CR3 is set and the CPU should b…
CVE-2025-5024High· 7.4A flaw was found in gnome-remote-desktop
A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, …
CVE-2025-46725HighLangroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
CVE-2025-37917High· 7.5net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll Use spin_lock_irqsave and spin_unlock_irqrestore instead of spin_lock and spin_unlock in mtk_…
CVE-2025-4948High· 7.5A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications
A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially cr…
CVE-2025-4969Medium· 6.5A vulnerability was found in the libsoup package
A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing …
CVE-2025-5150Medium· 6.3docarray prototype pollution
docarray prototype pollution
CVE-2025-5148Medium· 5.3FunAudioLLM InspireMusic deserialization vulnerability
FunAudioLLM InspireMusic deserialization vulnerability
Most-affected vendors
By CVEs published in the period.