Weekly digest
Week 28, 2025 (7–13 Jul)
A busier-than-usual week with 38 new CVEs (recent average about 26). Of those, 15 high. 5 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. transformers was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 38 published.
CVE-2025-49706Medium· 6.5CISA KEVPoCImproper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-48384High· 8.0CISA KEVPoCGit is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals
Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return a…
CVE-2025-53547High· 8.5PoChelm.sh/helm/v3: Helm Chart Code Execution (CVE-2025-53547)
A command injection vulnerability has been identified in Helm, a package manager for Kubernetes. An attacker can craft a malicious Chart.yaml file with specially linked dependencies in a Chart.lock file. If the Chart.lock file is a symboli…
CVE-2025-7425High· 7.8PoCA flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management
A flaw was found in libxslt where the attribute type, atype, flags are modified in a way that corrupts internal memory management. When XSLT functions, such as the key() process, result in tree fragments, this corruption prevents the pro…
CVE-2025-53513High· 8.8Juju zip slip vulnerability via authenticated endpoint
Juju zip slip vulnerability via authenticated endpoint
CVE-2025-30402High· 8.1ExecuTorch vulnerable to Heap-based Buffer Overflow attack
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
CVE-2025-5987High· 8.1A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This oc…
CVE-2025-7424High· 7.5A flaw was found in the libxslt library
A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can lead to type confusion during XML transformations. This vulnerability allows an attacker to crash the application…
CVE-2025-7346High· 7.5pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
CVE-2025-7345High· 7.5A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c)
A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur duri…
CVE-2025-6386High· 7.5Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
CVE-2025-6209High· 7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
Most-affected vendors
By CVEs published in the period.