Weekly digest
Week 37, 2025 (8–14 Sep)
A heavy week: 43 new CVEs, well above the recent average of about 26. Of those, 3 critical and 10 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 9.
New this week, ranked by depth score
The 12 that matter most of the 43 published.
CVE-2025-58180High· 8.8PoCOctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
CVE-2025-55835Critical· 9.8File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.
File Upload vulnerability in SueamCMS v.0.1.2 allows a remote attacker to execute arbitrary code via the lack of filtering.
CVE-2025-39758Critical· 9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"), we have been doing this: static int siw_t…
In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages Ever since commit c2ff29e99a76 ("siw: Inline do_tcp_sendpages()"), we have been doing this: static int siw_t…
CVE-2025-57833High· 7.1PoCDjango is subject to SQL injection through its column aliases
Django is subject to SQL injection through its column aliases
CVE-2025-52161Critical· 9.8Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.
Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2025-9086High· 7.51
1. A cookie is set using the `secure` keyword for `https://target` 2. curl is redirected to or otherwise made to speak with `http://target` (same hostname, but using clear text HTTP) using the same cookie set 3. The same cookie name i…
CVE-2025-39770High· 7.5net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension h…
CVE-2025-10193HighNeo4j Cypher MCP server is vulnerable to DNS rebinding
Neo4j Cypher MCP server is vulnerable to DNS rebinding
CVE-2025-59042HighPyInstaller has local privilege escalation vulnerability
PyInstaller has local privilege escalation vulnerability
CVE-2025-11059Highxml2rfc is vulnerable to arbitrary file reads through prepped files
xml2rfc is vulnerable to arbitrary file reads through prepped files
CVE-2025-57816High· 7.5Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
Fides Webserver API Rate Limiting Vulnerability in Proxied Environments
CVE-2025-10164High· 7.3SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
SGLang Remote Code Execution Vulnerability via Unsafe Deserialization in update_weights_from_tensor
Most-affected vendors
By CVEs published in the period.