Weekly digest
Week 34, 2025 (18–24 Aug)
19 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 8 high, 53% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 5.
New this week, ranked by depth score
The 12 that matter most of the 19 published.
CVE-2010-20103Critical· 9.8PoCA malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010
A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute a…
CVE-2025-38660Critical· 9.8[ceph] parse_longname(): strrchr() expects NUL-terminated string
In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build…
CVE-2025-9141High· 8.8vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder
CVE-2025-9236Medium· 6.3PoCA vulnerability has been found in Portabilis i-Educar up to 2.10
A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descri…
CVE-2025-71370High· 8.1Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper
CVE-2025-71348High· 8.1Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config
CVE-2025-38616High· 7.8In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the …
In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the …
CVE-2025-38614High· 7.8eventpoll: Fix semi-unbounded recursion
In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures t…
CVE-2025-57751HighDenial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs
CVE-2025-51529Medium· 5.3PoCIncorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…
Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…
CVE-2025-55201HighCopier's safe template has arbitrary filesystem read/write access
Copier's safe template has arbitrary filesystem read/write access
CVE-2025-51989High· 7.0HTML injection vulnerability in the registration interface in Evolution Consulting Kft
HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attacker to inject HTML tags into the "keresztnév" (firstname) field, which will be sent out in an email resulting in …
Most-affected vendors
By CVEs published in the period.