VulnSea

Weekly digest

Week 34, 2025 (18–24 Aug)

19 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 8 high, 53% of the total. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. linux was the most-affected vendor with 5.

19
New CVEs
2
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 19 published.

CVE-2010-20103Critical· 9.8PoC
1y ago

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010

A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute a…

Abyssalproftpd · proftpdEPSS 5.1%via NVD
CVE-2025-38660Critical· 9.8
1y ago

[ceph] parse_longname(): strrchr() expects NUL-terminated string

In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build…

MidnightLinux · LinuxEPSS 0.39%via CVEORG
CVE-2025-9141High· 8.8
1y ago

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

vLLM has remote code execution vulnerability in the tool call parser for Qwen3-Coder

Twilightvllm · vllmvia OSV
CVE-2025-9236Medium· 6.3PoC
1y ago

A vulnerability has been found in Portabilis i-Educar up to 2.10

A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/educar_tipo_usuario_lst.php of the component Tipos de usuàrio Page. Such manipulation of the argument nm_tipo/descri…

Twilightportabilis · i-educarEPSS 0.39%via NVD
CVE-2025-71370High· 8.1
1y ago

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Twilightpicklescan · picklescanEPSS 0.54%via GHSA
CVE-2025-71348High· 8.1
1y ago

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

Picklescan is missing detection when calling pytorch function torch.utils._config_module.load_config

Twilightpicklescan · picklescanEPSS 0.55%via OSV
CVE-2025-38616High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the …

In the Linux kernel, the following vulnerability has been resolved: tls: handle data disappearing from under the TLS ULP TLS expects that it owns the receive queue of the TCP socket. This cannot be guaranteed in case the reader of the …

Twilightlinux · linux_kernelEPSS 0.20%via NVD
CVE-2025-38614High· 7.8
1y ago

eventpoll: Fix semi-unbounded recursion

In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures t…

TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2025-57751High
1y ago

Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

Denial-of-Service attack in pyLoad CNL Blueprint using dukpy.evaljs

Twilightpyload-ng · pyload-ngEPSS 0.33%via OSV
CVE-2025-51529Medium· 5.3PoC
1y ago

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…

Incorrect Access Control in the AJAX endpoint functionality in jonkastonka Cookies and Content Security Policy plugin through version 2.29 allows remote attackers to cause a denial of service (database server resource exhaustion) via unl…

Twilightfollowmedarling · cookies_and_content_security_policyEPSS 0.44%via NVD
CVE-2025-55201High
1y ago

Copier's safe template has arbitrary filesystem read/write access

Copier's safe template has arbitrary filesystem read/write access

Twilightcopier · copierEPSS 0.26%via OSV
CVE-2025-51989High· 7.0
1y ago

HTML injection vulnerability in the registration interface in Evolution Consulting Kft

HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attacker to inject HTML tags into the "keresztnév" (firstname) field, which will be sent out in an email resulting in …

TwilightEPSS 0.40%via NVD

Most-affected vendors

By CVEs published in the period.