VulnSea

Weekly digest

Week 24, 2025 (9–15 Jun)

A busier-than-usual week with 35 new CVEs (recent average about 26). Of those, 2 critical and 10 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. salt was the most-affected vendor with 8.

35
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 35 published.

CVE-2025-5914High· 7.8PoC
1y ago

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function

A vulnerability has been identified in the libarchive library, specifically within the archive_read_format_rar_seek_data() function. This flaw involves an integer overflow that can ultimately lead to a double-free condition. Exploiting a…

▾ Midnightlibarchive · libarchiveEPSS 0.44%via NVD
CVE-2025-28388Critical· 9.8
1y ago

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.

▾ Midnightopenc3 · openc3EPSS 0.61%via OSV
CVE-2025-6021High· 7.5PoC
1y ago

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow

A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafte…

▾ Midnightxmlsoft · libxml2EPSS 1.4%via NVD
CVE-2025-28384Critical· 9.1
1y ago

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

▾ Midnightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-5915Medium· 6.6PoC
1y ago

A vulnerability has been identified in the libarchive library

A vulnerability has been identified in the libarchive library. This flaw can lead to a heap buffer over-read due to the size of a filter block potentially exceeding the Lempel-Ziv-Storer-Schieber (LZSS) window. This means the library may…

▾ Twilightlibarchive · libarchiveEPSS 0.19%via NVD
CVE-2025-22239High· 8.1
1y ago

Salt vulnerable to arbitrary event injection

Salt vulnerable to arbitrary event injection

▾ Twilightsalt · saltEPSS 0.18%via OSV
CVE-2025-22236High· 8.1
1y ago

Salt has minion event bus authorization bypass vulnerability

Salt has minion event bus authorization bypass vulnerability

▾ Twilightsalt · saltEPSS 0.17%via OSV
CVE-2025-49651High· 8.1
1y ago

Backend.AI Missing Authorization vulnerability

Backend.AI Missing Authorization vulnerability

▾ Twilightbackend-ai · backend-aiEPSS 0.34%via OSV
CVE-2025-49653High· 8.0
1y ago

BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

BackendAI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

▾ Twilightbackend-ai · backend-aiEPSS 0.35%via OSV
CVE-2025-28382High· 7.5
1y ago

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

An issue in the openc3-api/tables endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory traversal.

▾ Twilightopenc3 · openc3EPSS 0.89%via OSV
CVE-2025-28381High· 7.5
1y ago

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all co…

A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

▾ Twilightopenc3 · openc3EPSS 0.52%via OSV
CVE-2025-22874High· 7.5
1y ago

crypto/x509: Usage of ExtKeyUsageAny disables policy validation in crypto/x509 (CVE-2025-22874)

A flaw was found in Go's crypto/x509 package. This vulnerability allows improper certificate validation, bypassing policy constraints via using ExtKeyUsageAny in VerifyOptions.KeyUsages.

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4.20EPSS 0.37%via CSAF

Most-affected vendors

By CVEs published in the period.