VulnSea

Weekly digest

Week 23, 2025 (2–8 Jun)

20 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 7 high, 50% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries.

20
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2025-4517Critical· 9.4PoC
1y ago

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() o…

Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affected by this vulnerability if using the tarfile module to extract untrusted tar archives using TarFile.extractall() o…

▾ AbyssalEPSS 1.4%via NVD
CVE-2025-49619High· 8.5PoC
1y ago

Skyvern has a Jinja runtime leak

Skyvern has a Jinja runtime leak

▾ Midnightskyvern · skyvernEPSS 20%via OSV
CVE-2025-1793Critical· 9.8
1y ago

llama_index vulnerable to SQL Injection

llama_index vulnerable to SQL Injection

▾ Midnightllama-index · llama-indexEPSS 0.66%via OSV
CVE-2025-4138High· 7.5PoC
1y ago

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

▾ MidnightEPSS 1.4%via NVD
CVE-2025-1750Critical· 9.8
1y ago

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnera…

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write ar…

▾ Midnightllama-index · llama-indexEPSS 0.82%via OSV
CVE-2025-3260High· 8.3
1y ago

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

Grafana vulnerable to authenticated users bypassing dashboard, folder permissions

▾ Twilightgrafana · github.com/grafana/grafanaEPSS 0.56%via OSV
CVE-2025-48957High· 7.5
1y ago

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

AstrBot Has Path Traversal Vulnerability in /api/chat/get_file

▾ Twilightastrbot · astrbotEPSS 0.74%via OSV
CVE-2025-4435High· 7.5
1y ago

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted

When using a TarFile.errorlevel = 0 and extracting with a filter the documented behavior is that any filtered members would be skipped and not extracted. However the actual behavior of TarFile.errorlevel = 0 in affected versions is that …

▾ TwilightEPSS 0.59%via NVD
CVE-2025-4330High· 7.5
1y ago

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

Allows the extraction filter to be ignored, allowing symlink targets to point outside the destination directory, and the modification of some file metadata. You are affected by this vulnerability if using the tarfile module to extract …

▾ TwilightEPSS 0.94%via NVD
CVE-2025-30167High· 7.3
1y ago

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability

▾ Twilightjupyter-core · jupyter-coreEPSS 0.19%via OSV
CVE-2025-20278Medium· 6.0
1y ago

Cisco Unified Communications Products Command Injection Vulnerability (CVE-2025-20278)

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vuln…

▾ SunlitCisco · Cisco Unified Communications ManagerEPSS 0.18%via CSAF
CVE-2025-5683Medium· 5.5
1y ago

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.  This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.

▾ Sunlitqt · qtEPSS 0.24%via NVD

Most-affected vendors

By CVEs published in the period.