Weekly digest
Week 32, 2025 (4–10 Aug)
21 new CVEs this week, in line with the recent average. Of those, 2 critical and 5 high. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. openbao was the most-affected vendor with 7.
New this week, ranked by depth score
The 12 that matter most of the 21 published.
CVE-2025-8088High· 8.8CISA KEVPoCA path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepano…
CVE-2025-20701High· 8.8PoCIn the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not nee…
CVE-2025-54802Critical· 9.8pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
CVE-2025-54997Critical· 9.1Privileged OpenBao Operator May Execute Code on the Underlying Host
Privileged OpenBao Operator May Execute Code on the Underlying Host
CVE-2025-54886High· 8.4SKOPS Card.get_model happily allows arbitrary code execution
SKOPS Card.get_model happily allows arbitrary code execution
CVE-2025-54796High· 7.5copyparty allows Regex Denial of Service (ReDoS) in the upload listing
copyparty allows Regex Denial of Service (ReDoS) in the upload listing
CVE-2025-54996High· 7.2OpenBao Root Namespace Operator May Elevate Token Privileges
OpenBao Root Namespace Operator May Elevate Token Privileges
CVE-2025-55001Medium· 6.5OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
CVE-2025-55000Medium· 6.5OpenBao TOTP Secrets Engine Code Reuse
OpenBao TOTP Secrets Engine Code Reuse
CVE-2025-6013Medium· 6.5HashiCorp Vault ldap auth method may not have correctly enforced MFA
HashiCorp Vault ldap auth method may not have correctly enforced MFA
CVE-2025-7195Medium· 6.4Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID
Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/p…
CVE-2025-55003Medium· 5.7OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
Most-affected vendors
By CVEs published in the period.