Weekly digest
Week 22, 2025 (26 May – 1 Jun)
28 new CVEs this week, in line with the recent average. Of those, 3 critical and 9 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. vllm was the most-affected vendor with 7.
New this week, ranked by depth score
The 12 that matter most of the 28 published.
CVE-2025-48938Critical· 9.8go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier
go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing …
CVE-2025-5222High· 7.0PoCA stack buffer overflow was found in Internationl components for unicode (ICU )
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary…
CVE-2025-44619Critical· 9.1Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.
Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.
CVE-2025-47933Critical· 9.0Argo CD allows cross-site scripting on repositories page
Argo CD allows cross-site scripting on repositories page
CVE-2025-48383High· 8.2Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
Django-Select2 Vulnerable to Widget Instance Secret Cache Key Leaking
CVE-2025-1753High· 7.8LLama-Index CLI OS command injection vulnerability
LLama-Index CLI OS command injection vulnerability
CVE-2025-48912HighApache Superset: Improper authorization bypass on row level security via SQL Injection
Apache Superset: Improper authorization bypass on row level security via SQL Injection
CVE-2025-5276High· 7.4Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function
Versions of the package mcp-markdownify-server before 1.0.0 are vulnerable to Server-Side Request Forgery (SSRF) via the Markdownify.get() function. An attacker can craft a prompt that, once accessed by the MCP host, can invoke the webpa…
CVE-2025-5279High· 7.5Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
Issue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider plugin
CVE-2025-48798High· 7.3A flaw was found in GIMP when processing XCF image files
A flaw was found in GIMP when processing XCF image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to crashes and …
CVE-2025-48797High· 7.3A flaw was found in GIMP when processing certain TGA image files
A flaw was found in GIMP when processing certain TGA image files. If a user opens one of these image files that has been specially crafted by an attacker, GIMP can be tricked into making serious memory errors, potentially leading to cras…
CVE-2025-48796High· 7.3A flaw was found in GIMP
A flaw was found in GIMP. The GIMP ani_load_image() function is vulnerable to a stack-based overflow. If a user opens.ANI files, GIMP may be used to store more information than the capacity allows. This flaw allows a malicious ANI file t…
Most-affected vendors
By CVEs published in the period.