VulnSea

Weekly digest

Week 36, 2025 (1–7 Sep)

30 new CVEs this week, in line with the recent average. Of those, 1 critical and 11 high. 6 arrived with exploitation evidence or public exploit code already attached. CISA added 2 CVEs to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 12.

30
New CVEs
1
Critical
2
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 30 published.

CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

Hadallinux · linux_kernelEPSS 2.0%via NVD
CVE-2025-55190High· 8.8PoC
1y ago

github.com/argoproj/argo-cd: Project API Token Exposes Repository Credentials (CVE-2025-55190)

An information leak was discovered in how Argo CD handles API tokens. The project details API endpoint could provide unintentional access to sensitive repository credentials.

MidnightRed Hat · Red Hat OpenShift GitOps 1.17EPSS 5.3%via CSAF
CVE-2025-57808High· 8.1PoC
1y ago

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

ESP-IDF web_server basic auth bypass using empty or incomplete Authorization header

Midnightesphome · esphomeEPSS 1.6%via OSV
CVE-2025-9784High· 7.5PoC
1y ago

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters

A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive serv…

Midnightredhat · build_of_apache_camel_for_spring_bootEPSS 2.3%via NVD
CVE-2025-10072Medium· 6.3PoC
1y ago

A vulnerability was found in Portabilis i-Educar up to 2.10

A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /matricula/[ID_STUDENT]/enturmar/. Performing a manipulation results in improper access controls. It is possible to initi…

Twilightportabilis · i-educarEPSS 0.32%via NVD
CVE-2025-10012Medium· 6.3PoC
1y ago

A security vulnerability has been detected in Portabilis i-Educar up to 2.10

A security vulnerability has been detected in Portabilis i-Educar up to 2.10. The impacted element is an unknown function of the file educar_historico_escolar_lst.php. Such manipulation of the argument ref_cod_aluno leads to sql injectio…

Twilightportabilis · i-educarEPSS 0.37%via NVD
CVE-2025-58375High· 8.1
1y ago

Frappe is a full-stack web application framework

Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecure endpoint parameter that is vulnerable to error-based SQL Injection through lack of validation. Sensitive informatio…

TwilightEPSS 0.34%via NVD
CVE-2025-9566High· 8.1
1y ago

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path

There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube file container a Secrete or a ConfigMap volume mount and such volume contains a symbolic link to a host file path. In…

TwilightRed Hat · podmanEPSS 1.1%via NVD
CVE-2025-9636High· 7.9
1y ago

pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability

pgadmin4 is affected by a Cross-Origin Opener Policy (COOP) vulnerability

Twilightpgadmin4 · pgadmin4EPSS 0.21%via OSV
CVE-2025-55671High· 7.8
1y ago

TkEasyGUI Affected by Uncontrolled Search Path Element Issue

TkEasyGUI Affected by Uncontrolled Search Path Element Issue

Twilighttkeasygui · tkeasyguiEPSS 0.16%via OSV
CVE-2025-39691High· 7.8
1y ago

fs/buffer: fix use-after-free when call bh_read() helper

In the Linux kernel, the following vulnerability has been resolved: fs/buffer: fix use-after-free when call bh_read() helper There's issue as follows: BUG: KASAN: stack-out-of-bounds in end_buffer_read_sync+0xe3/0x110 Read of size 8 at…

TwilightLinux · LinuxEPSS 0.18%via CVEORG
CVE-2025-9189High· 7.8
1y ago

There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab

There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful…

Twilightni · dasylabEPSS 0.28%via NVD

Most-affected vendors

By CVEs published in the period.