VulnSea

Weekly digest

Week 32, 2025 (4–10 Aug)

21 new CVEs this week, in line with the recent average. Of those, 2 critical and 5 high. 4 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. openbao was the most-affected vendor with 7.

21
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 21 published.

CVE-2025-8088High· 8.8CISA KEVPoC
1y ago

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepano…

Abyssalrarlab · winrarEPSS 94%via NVD
CVE-2025-20701High· 8.8PoC
1y ago

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent

In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not nee…

MidnightAiroha Technology Corp. · AB156x, AB157x, AB158x, AB159x seriesEPSS 8.7%via NVD
CVE-2025-54802Critical· 9.8
1y ago

pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)

pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)

Midnightpyload-ng · pyload-ngEPSS 1.2%via OSV
CVE-2025-54997Critical· 9.1
1y ago

Privileged OpenBao Operator May Execute Code on the Underlying Host

Privileged OpenBao Operator May Execute Code on the Underlying Host

Midnightopenbao · github.com/openbao/openbaoEPSS 0.38%via OSV
CVE-2025-54886High· 8.4
1y ago

SKOPS Card.get_model happily allows arbitrary code execution

SKOPS Card.get_model happily allows arbitrary code execution

Twilightskops · skopsEPSS 0.22%via OSV
CVE-2025-54796High· 7.5
1y ago

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

copyparty allows Regex Denial of Service (ReDoS) in the upload listing

Twilightcopyparty · copypartyEPSS 0.42%via OSV
CVE-2025-54996High· 7.2
1y ago

OpenBao Root Namespace Operator May Elevate Token Privileges

OpenBao Root Namespace Operator May Elevate Token Privileges

Twilightopenbao · github.com/openbao/openbaoEPSS 0.31%via OSV
CVE-2025-55001Medium· 6.5
1y ago

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.22%via OSV
CVE-2025-55000Medium· 6.5
1y ago

OpenBao TOTP Secrets Engine Code Reuse

OpenBao TOTP Secrets Engine Code Reuse

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.21%via OSV
CVE-2025-6013Medium· 6.5
1y ago

HashiCorp Vault ldap auth method may not have correctly enforced MFA

HashiCorp Vault ldap auth method may not have correctly enforced MFA

Sunlithashicorp · github.com/hashicorp/vaultEPSS 0.50%via OSV
CVE-2025-7195Medium· 6.4
1y ago

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID

Early versions of Operator-SDK provided an insecure method to allow operator containers to run in environments that used a random UID. Operator-SDK before 0.15.2 provided a script, user_setup, which modifies the permissions of the /etc/p…

Sunlitoperator-framework · operator-sdkEPSS 0.22%via NVD
CVE-2025-55003Medium· 5.7
1y ago

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse

Sunlitopenbao · github.com/openbao/openbaoEPSS 0.20%via OSV

Most-affected vendors

By CVEs published in the period.