VulnSea

Weekly digest

Week 35, 2025 (25–31 Aug)

A heavy week: 42 new CVEs, well above the recent average of about 24. Of those, 3 critical and 12 high. 7 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. picklescan was the most-affected vendor with 15.

42
New CVEs
3
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 42 published.

CVE-2025-34157Critical· 9.0PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name con…

Abyssalcoollabs · coolifyEPSS 0.46%via NVD
CVE-2005-10004High· 8.8PoC
1y ago

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script

Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the graph_start GET parameter, which is improperly handled durin…

Midnightcacti · cactiEPSS 2.0%via NVD
CVE-2025-34161High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow

Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary shell …

Midnightcoollabs · coolifyEPSS 3.0%via NVD
CVE-2025-34159High· 8.8PoC
1y ago

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow

Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Do…

Midnightcoollabs · coolifyEPSS 0.96%via NVD
CVE-2025-8067High· 8.5PoC
1y ago

A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system

A flaw was found in the Udisks daemon, where it allows unprivileged users to create loop devices using the D-BUS system. This is achieved via the loop device handler, which handles requests sent through the D-BUS interface. As two of the…

MidnightEPSS 0.65%via NVD
CVE-2025-58050Critical· 9.1
1y ago

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow re…

The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the han…

Midnightpcre2 · pcre2EPSS 0.80%via OSV
CVE-2025-55526Critical· 9.1
1y ago

n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py

n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py

Midnightzie619 · n8n_workflow_collectionEPSS 0.81%via NVD
CVE-2025-57760High· 8.8
1y ago

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

Langflow Vulnerable to Privilege Escalation via CLI Superuser Creation (Post-RCE)

Twilightlangflow · langflowEPSS 0.48%via OSV
CVE-2025-9606Medium· 6.3PoC
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/agenda_preferencias.php. Performing a manipulation of the argument cod_agenda results in sql…

Twilightportabilis · i-educarEPSS 0.34%via NVD
CVE-2025-9531Medium· 6.3PoC
1y ago

A vulnerability was detected in Portabilis i-Educar up to 2.10

A vulnerability was detected in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet/agenda.php of the component Agenda Module. Performing a manipulation of the argument cod_agenda results in sql injecti…

Twilightportabilis · i-educarEPSS 0.40%via NVD
CVE-2025-5302High· 8.6
1y ago

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

LlamaIndex affected by a Denial of Service (DOS) in JSONReader

Twilightllama-index-core · llama-index-coreEPSS 0.29%via OSV
CVE-2023-41471High· 7.8
1y ago

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to t…

Cross Site Scripting vulnerability in copyparty before 1.9.2 allows a local attacker to execute arbitrary code via a crafted payload to the WEEKEND-PLANS function. NOTE: this is disputed because WEEKEND-PLANS is accessible only to actors…

Twilightcopyparty · copypartyEPSS 0.26%via OSV

Most-affected vendors

By CVEs published in the period.