VulnSea

Weekly digest

Week 31, 2025 (28 Jul – 3 Aug)

A busier-than-usual week with 36 new CVEs (recent average about 27). Of those, 3 critical and 8 high. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. materialx was the most-affected vendor with 4.

36
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 36 published.

CVE-2025-31277High· 8.8CISA KEVPoC
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…

Abyssalapple · safariEPSS 1.5%via NVD
CVE-2025-54381Critical· 9.9PoC
1y ago

BentoML SSRF Vulnerability in File Upload Processing

BentoML SSRF Vulnerability in File Upload Processing

Abyssalbentoml · bentomlEPSS 14%via OSV
CVE-2023-32256High· 7.50day
1y ago

A flaw was found in the Linux kernel's ksmbd component

A flaw was found in the Linux kernel's ksmbd component. A race condition between smb2 close operation and logoff in multichannel connections could result in a use-after-free issue.

AbyssalEPSS 0.53%via NVD
CVE-2025-50460Critical· 9.8PoC
1y ago

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

MS SWIFT Remote Code Execution via unsafe PyYAML deserialization

Abyssalms-swift · ms-swiftEPSS 2.5%via OSV
CVE-2023-32255Medium· 5.30day
1y ago

A flaw was found in the Linux kernel's ksmbd component

A flaw was found in the Linux kernel's ksmbd component. A memory leak can occur if a client sends a session setup request with an unknown NTLMSSP message type, potentially leading to resource exhaustion.

MidnightEPSS 0.48%via NVD
GHSA-jxr6-qrxx-2ph2Critical
1y ago

num2words subjected to phishing attack, two versions published containing malware

num2words subjected to phishing attack, two versions published containing malware

Midnightnum2words · num2wordsvia OSV
CVE-2025-54589Medium· 6.3PoC
1y ago

copyparty Reflected XSS via Filter Parameter

copyparty Reflected XSS via Filter Parameter

Twilightcopyparty · copypartyEPSS 2.4%via OSV
CVE-2023-32251Low· 3.70day
1y ago

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server)

A vulnerability has been identified in the Linux kernel's ksmbd component (kernel SMB/CIFS server). A security control designed to prevent dictionary attacks, which introduces a 5-second delay during session setup, can be bypassed throug…

TwilightEPSS 0.44%via NVD
CVE-2025-48071High· 7.8
1y ago

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

OpenEXR Heap-Based Buffer Overflow in Deep Scanline Parsing via Forged Unpacked Size

Twilightopenexr · openexrEPSS 0.31%via OSV
CVE-2025-54576High· 7.4
1y ago

github.com/oauth2-proxy/oauth2-proxy: OAuth2-Proxy authentication bypass (CVE-2025-54576)

An authentication bypass flaw was found in the OAuth2-Proxy project. This bypass affects systems that have configured their deployment to skip authentication on endpoints that match a deployment-defined regular expression. HTTP parameters …

TwilightRed Hat · Red Hat Ceph Storage 8EPSS 1.2%via CSAF
CVE-2025-54433High
1y ago

Bugsink path traversal via event_id in ingestion

Bugsink path traversal via event_id in ingestion

Twilightbugsink · bugsinkEPSS 0.56%via OSV
CVE-2025-8194High· 7.5
1y ago

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs

There is a defect in the CPython “tarfile” module affecting the “TarFile” extraction and entry enumeration APIs. The tar implementation would process tar archives with negative offsets without error, resulting in an infinite loop and dea…

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via NVD

Most-affected vendors

By CVEs published in the period.