VulnSea

Weekly digest

Week 28, 2025 (7–13 Jul)

A busier-than-usual week with 38 new CVEs (recent average about 26). Of those, 15 high. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. transformers was the most-affected vendor with 5.

38
New CVEs
0
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 38 published.

CVE-2025-49706Medium· 6.5CISA KEVPoC
1y ago

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Midnightmicrosoft · sharepoint_enterprise_serverEPSS 99%via NVD
CVE-2025-48384High· 8.0CISA KEVPoC
1y ago

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return a…

Abyssalgit-scm · gitEPSS 4.1%via NVD
CVE-2025-53547High· 8.5PoC
1y ago

helm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)

A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…

MidnightRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.13 for RHEL 9EPSS 0.38%via CSAF
CVE-2025-7425High· 7.8PoC
1y ago

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management

A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the pro…

MidnightGNOME · libxml2EPSS 0.36%via NVD
CVE-2025-53513High· 8.8
1y ago

Juju zip slip vulnerability via authenticated endpoint

Juju zip slip vulnerability via authenticated endpoint

Twilightjuju · github.com/juju/jujuEPSS 0.66%via OSV
CVE-2025-30402High· 8.1
1y ago

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

ExecuTorch vulnerable to Heap-based Buffer Overflow attack

Twilightexecutorch · executorchEPSS 0.36%via OSV
CVE-2025-5987High· 8.1
1y ago

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library

A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This oc…

Twilightlibssh · libsshEPSS 1.5%via NVD
CVE-2025-7424High· 7.5
1y ago

A flaw was found in the libxslt library

A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application…

Twilightxmlsoft · libxsltEPSS 1.2%via NVD
CVE-2025-7346High· 7.5
1y ago

pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages

pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages

Twilightpyload-ng · pyload-ngEPSS 0.32%via OSV
CVE-2025-7345High· 7.5
1y ago

A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c)

A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur duri…

TwilightEPSS 1.2%via NVD
CVE-2025-6386High· 7.5
1y ago

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function

Twilightlollms · lollmsEPSS 0.37%via OSV
CVE-2025-6209High· 7.5
1y ago

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

LlamaIndex vulnerable to Path Traversal attack through its encode_image function

Twilightllama-index-core · llama-index-coreEPSS 0.55%via OSV

Most-affected vendors

By CVEs published in the period.