Weekly digest
Week 30, 2025 (21–27 Jul)
18 new CVEs this week, in line with the recent average. Severity skewed high: 9 high, 50% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
CVE-2025-49706Medium· 6.5CISA KEVPoCImproper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-6558High· 8.8CISA KEVPoCInsufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
New this week, ranked by depth score
The 12 that matter most of the 18 published.
CVE-2025-38352High· 7.8CISA KEVPoCIn the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…
In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…
CVE-2025-6018High· 7.8PoCA Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)
A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the…
CVE-2025-54379High· 9.8eKuiper API endpoints handling SQL queries with user-controlled table names.
eKuiper API endpoints handling SQL queries with user-controlled table names.
CVE-2025-6998HighPoCCalibre Web and Autocaliweb have a ReDoS vulnerability
Calibre Web and Autocaliweb have a ReDoS vulnerability
CVE-2025-54413HighSkops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time
CVE-2025-54412HighSkops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution
CVE-2025-54365HighFastAPI Guard has a regex bypass
FastAPI Guard has a regex bypass
CVE-2025-7962High· 7.5In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.
CVE-2025-54140High· 7.5`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
CVE-2025-7404MediumPoCCalibre Web and Autocaliweb have OS Command Injection vulnerability
Calibre Web and Autocaliweb have OS Command Injection vulnerability
CVE-2025-5449Medium· 6.5A flaw was found in the SFTP server message decoding logic of libssh
A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to faile…
CVE-2025-51481Medium· 6.6Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read a…
Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookD…
Most-affected vendors
By CVEs published in the period.