VulnSea

Weekly digest

Week 30, 2025 (21–27 Jul)

18 new CVEs this week, in line with the recent average. Severity skewed high: 9 high, 50% of the total. 5 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog.

18
New CVEs
0
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 18 published.

CVE-2025-38352High· 7.8CISA KEVPoC
1y ago

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…

Abyssallinux · linux_kernelEPSS 1.3%via NVD
CVE-2025-6018High· 7.8PoC
1y ago

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM)

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM). This flaw allows an unprivileged local attacker (for example, a user logged in via SSH) to obtain the…

Midnightsuse · pam-configEPSS 1.1%via NVD
CVE-2025-54379High· 9.8
1y ago

eKuiper API endpoints handling SQL queries with user-controlled table names.

eKuiper API endpoints handling SQL queries with user-controlled table names.

Twilightlf-edge · github.com/lf-edge/ekuiper/v2EPSS 0.77%via OSV
CVE-2025-6998HighPoC
1y ago

Calibre Web and Autocaliweb have a ReDoS vulnerability

Calibre Web and Autocaliweb have a ReDoS vulnerability

Midnightcalibreweb · calibrewebEPSS 0.84%via OSV
CVE-2025-54413High
1y ago

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

Skops may allow MethodNode to access unexpected object fields through dot notation, leading to arbitrary code execution at load time

Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-54412High
1y ago

Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution

Skops has Inconsistent Trusted Type Validation that Enables Hidden `operator` Methods Execution

Twilightskops · skopsEPSS 0.14%via OSV
CVE-2025-54365High
1y ago

FastAPI Guard has a regex bypass

FastAPI Guard has a regex bypass

Twilightfastapi-guard · fastapi-guardEPSS 0.76%via OSV
CVE-2025-7962High· 7.5
1y ago

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

Twilighteclipse · jakarta_mailEPSS 0.77%via NVD
CVE-2025-54140High· 7.5
1y ago

`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write

`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write

Twilightpyload-ng · pyload-ngEPSS 0.65%via OSV
CVE-2025-7404MediumPoC
1y ago

Calibre Web and Autocaliweb have OS Command Injection vulnerability

Calibre Web and Autocaliweb have OS Command Injection vulnerability

Twilightcalibreweb · calibrewebEPSS 2.8%via OSV
CVE-2025-5449Medium· 6.5
1y ago

A flaw was found in the SFTP server message decoding logic of libssh

A flaw was found in the SFTP server message decoding logic of libssh. The issue occurs due to an incorrect packet length check that allows an integer overflow when handling large payload sizes on 32-bit systems. This issue leads to faile…

Sunlitlibssh · libsshEPSS 0.84%via NVD
CVE-2025-51481Medium· 6.6
1y ago

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read a…

Local File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbitrary files by supplying path traversal sequences in the notebook_path field of ExternalNotebookD…

Sunlitdagster-ge · dagster-geEPSS 0.55%via OSV

Most-affected vendors

By CVEs published in the period.