VulnSea

Weekly digest

Week 29, 2025 (14–20 Jul)

20 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 7 high, 50% of the total. 8 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

20
New CVEs
3
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2025-53770Critical· 9.8CISA KEV0dayPoC
1y ago

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

Hadalmicrosoft · sharepoint_serverEPSS 100%via NVD
CVE-2025-6558High· 8.8CISA KEVPoC
1y ago

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Abyssalgoogle · chromeEPSS 9.6%via NVD
CVE-2025-6965High· 7.7PoC
1y ago

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available

There exists a vulnerability in SQLite versions before 3.50.2 where the number of aggregate terms could exceed the number of columns available. This could lead to a memory corruption issue. We recommend upgrading to version 3.50.2 or above.

Midnightsqlite · sqliteEPSS 73%via NVD
CVE-2015-10138Critical· 9.8PoC
1y ago

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2

The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it p…

Abyssallyntonreed · work_the_flow_file_uploadEPSS 3.6%via NVD
CVE-2025-34115High· 8.7PoC
1y ago

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' featur…

MidnightITRS Group · OP5 MonitorEPSS 3.3%via NVD
CVE-2025-53890Critical· 9.8
1y ago

pyLoad vulnerable to XSS through insecure CAPTCHA

pyLoad vulnerable to XSS through insecure CAPTCHA

Midnightpyload-ng · pyload-ngEPSS 1.2%via OSV
CVE-2025-38349High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still holding the ep mutex Jann Horn points out that epoll is decrementing the ep refcount and then doing a mutex_unl…

In the Linux kernel, the following vulnerability has been resolved: eventpoll: don't decrement ep refcount while still holding the ep mutex Jann Horn points out that epoll is decrementing the ep refcount and then doing a mutex_unl…

Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2025-22868High· 7.5
1y ago

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

golang.org/x/oauth2 Improper Validation of Syntactic Correctness of Input vulnerability

Twilightx · golang.org/x/oauth2EPSS 0.87%via OSV
CVE-2025-53893High
1y ago

File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing

File Browser's Uncontrolled Memory Consumption vulnerability can enable DoS attack due to oversized file processing

Twilightfilebrowser · github.com/filebrowser/filebrowser/v2EPSS 0.36%via OSV
CVE-2025-53826High
1y ago

File Browser’s insecure JWT handling can lead to session replay attacks after logout

File Browser’s insecure JWT handling can lead to session replay attacks after logout

Twilightfilebrowser · github.com/filebrowser/filebrowserEPSS 0.50%via OSV
CVE-2025-53640MediumPoC
1y ago

Indico vulnerability allows attackers to bulk dump user details

Indico vulnerability allows attackers to bulk dump user details

Twilightindico · indicoEPSS 0.60%via OSV
CVE-2025-7519Medium· 6.7
1y ago

A flaw was found in polkit

A flaw was found in polkit. When processing an XML policy with 32 or more nested elements in depth, an out-of-bounds write can be triggered. This issue can lead to a crash or other unexpected behavior, and arbitrary code execution is not…

Sunlitredhat · openshift_container_platformEPSS 0.19%via NVD

Most-affected vendors

By CVEs published in the period.