VulnSea

Weekly digest

Week 27, 2025 (30 Jun – 6 Jul)

19 new CVEs this week, in line with the recent average. Severity skewed high: 11 high, 58% of the total. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 10.

19
New CVEs
0
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 19 published.

CVE-2025-34088High· 8.8PoC
1y ago

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier

An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php functionality allows authenticated users to execute arbitrary OS commands via the select_ips parameter when performin…

▾ Midnightpandorafms · pandora_fmsEPSS 7.3%via NVD
CVE-2025-6297High· 8.2
1y ago

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data

It was discovered that dpkg-deb does not properly sanitize directory permissions when extracting a control member into a temporary directory, which is documented as being a safe operation even on untrusted data. This may result in leavin…

▾ Twilightdebian · dpkgEPSS 0.38%via NVD
CVE-2025-53366High
1y ago

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS

▾ Twilightmcp · mcpEPSS 7.3%via OSV
CVE-2025-38232High· 7.8
1y ago

NFSD: fix race between nfsd registration and exports_proc

In the Linux kernel, the following vulnerability has been resolved: NFSD: fix race between nfsd registration and exports_proc As of now nfsd calls create_proc_exports_entry() at start of init_nfsd and cleanup by remove_proc_entry() at …

▾ TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2025-38206High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return er…

In the Linux kernel, the following vulnerability has been resolved: exfat: fix double free in delayed_free The double free could happen in the following path. exfat_create_upcase_table() exfat_create_upcase_table() : return er…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2025-38192High· 7.8
1y ago

net: clear the dst when changing skb protocol

In the Linux kernel, the following vulnerability has been resolved: net: clear the dst when changing skb protocol A not-so-careful NAT46 BPF program can crash the kernel if it indiscriminately flips ingress packets from v4 to v6: BU…

▾ TwilightLinux · LinuxEPSS 0.17%via CVEORG
CVE-2025-38162High· 7.8
1y ago

netfilter: nft_set_pipapo: prevent overflow in lookup table allocation

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: prevent overflow in lookup table allocation When calculating the lookup table size, ensure the following multiplication does not overflow: …

▾ TwilightLinux · LinuxEPSS 0.17%via CVEORG
CVE-2025-38117High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Protect mgmt_pending list with its own lock This uses a mutex to protect from concurrent access of mgmt_pending list which can cause crashes like: ==…

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Protect mgmt_pending list with its own lock This uses a mutex to protect from concurrent access of mgmt_pending list which can cause crashes like: ==…

▾ Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2025-38097High· 7.8
1y ago

espintcp: remove encap socket caching to avoid reference leak

In the Linux kernel, the following vulnerability has been resolved: espintcp: remove encap socket caching to avoid reference leak The current scheme for caching the encap socket can lead to reference leaks when we try to delete the net…

▾ TwilightLinux · LinuxEPSS 0.19%via CVEORG
CVE-2025-53365High
1y ago

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service

▾ Twilightmcp · mcpEPSS 0.37%via OSV
CVE-2025-48379High· 7.1
1y ago

Pillow is a Python imaging library

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without …

▾ Twilightpython · pillowEPSS 0.30%via NVD
CVE-2025-5351Medium· 6.5
1y ago

A flaw was found in the key export functionality of libssh

A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for converting cryptographic keys into serialized formats. During error handling, a memory structure is freed but not clear…

▾ Sunlitlibssh · libsshEPSS 0.53%via NVD

Most-affected vendors

By CVEs published in the period.