Weekly digest
Week 24, 2025 (9–15 Jun)
A busier-than-usual week with 35 new CVEs (recent average about 26). Of those, 2 critical and 10 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. salt was the most-affected vendor with 8.
New this week, ranked by depth score
The 12 that matter most of the 35 published.
CVE-2025-5914High· 7.8PoCA vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function
A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a…
CVE-2025-28388Critical· 9.8OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
CVE-2025-6021High· 7.5PoCA flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…
CVE-2025-28384Critical· 9.1An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
CVE-2025-5915Medium· 6.6PoCA vulnerability has been identified in the libarchive library
A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may…
CVE-2025-22239High· 8.1Salt vulnerable to arbitrary event injection
Salt vulnerable to arbitrary event injection
CVE-2025-22236High· 8.1Salt has minion event bus authorization bypass vulnerability
Salt has minion event bus authorization bypass vulnerability
CVE-2025-49651High· 8.1Backend.AI Missing Authorization vulnerability
Backend.AI Missing Authorization vulnerability
CVE-2025-49653High· 8.0BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-28382High· 7.5An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.
CVE-2025-28381High· 7.5A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all co…
A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.
CVE-2025-22874High· 7.5crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)
A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.
Most-affected vendors
By CVEs published in the period.