VulnSea

Weekly digest

Week 38, 2025 (15–21 Sep)

32 new CVEs this week, in line with the recent average. Severity skewed high: 4 critical and 12 high, 50% of the total. 6 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 17.

32
New CVEs
4
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 32 published.

CVE-2025-10035Critical· 10.0CISA KEVPoC
1y ago

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

Hadalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2025-9242Critical· 9.8CISA KEVPoC
1y ago

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…

Hadalwatchguard · firewareEPSS 91%via NVD
CVE-2025-57174Critical· 9.8PoC
1y ago

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions

An issue was discovered in Siklu Communications Etherhaul 8010TX and 1200FX devices, Firmware 7.4.0 through 10.7.3 and possibly other previous versions. The rfpiped service listening on TCP port 555 which uses static AES encryption keys …

AbyssalEPSS 2.2%via NVD
CVE-2025-39866High· 7.8PoC
1y ago

fs: writeback: fix use-after-free in __mark_inode_dirty()

In the Linux kernel, the following vulnerability has been resolved: fs: writeback: fix use-after-free in __mark_inode_dirty() An use-after-free issue occurred when __mark_inode_dirty() get the bdi_writeback that was in the progress of …

MidnightLinux · LinuxEPSS 0.31%via CVEORG
CVE-2025-59341HighPoC
1y ago

esm.sh has File Inclusion issue

esm.sh has File Inclusion issue

Midnightesm-dev · github.com/esm-dev/esm.shEPSS 1.6%via OSV
CVE-2025-57631Critical· 9.8
1y ago

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file upload module

Midnighttduckcloud · tduckEPSS 0.82%via NVD
CVE-2025-39827High· 8.8
1y ago

net: rose: include node references in rose_neigh refcount

In the Linux kernel, the following vulnerability has been resolved: net: rose: include node references in rose_neigh refcount Current implementation maintains two separate reference counting mechanisms: the 'count' field in struct rose…

TwilightLinux · LinuxEPSS 0.21%via CVEORG
CVE-2025-39826High· 8.8
1y ago

net: rose: convert 'use' field to refcount_t

In the Linux kernel, the following vulnerability has been resolved: net: rose: convert 'use' field to refcount_t The 'use' field in struct rose_neigh is used as a reference counter but lacks atomicity. This can lead to race conditions …

TwilightLinux · LinuxEPSS 0.20%via CVEORG
CVE-2022-50393High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: SDMA update use unlocked iterator SDMA update page table may be called from unlocked context, this generate below warning

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: SDMA update use unlocked iterator SDMA update page table may be called from unlocked context, this generate below warning. Use unlocked iterator to handle …

Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2022-50378High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: drm/meson: reorder driver deinit sequence to fix use-after-free bug Unloading the driver triggers the following KASAN warning: [ +0.006275] =========================…

In the Linux kernel, the following vulnerability has been resolved: drm/meson: reorder driver deinit sequence to fix use-after-free bug Unloading the driver triggers the following KASAN warning: [ +0.006275] =========================…

Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2022-50303High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix double release compute pasid If kfd_process_device_init_vm returns failure after vm is converted to compute vm and vm->pasid set to compute pasid, KFD …

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix double release compute pasid If kfd_process_device_init_vm returns failure after vm is converted to compute vm and vm->pasid set to compute pasid, KFD …

Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2022-50256High· 7.8
1y ago

In the Linux kernel, the following vulnerability has been resolved: drm/meson: remove drm bridges at aggregate driver unbind time drm bridges added by meson_encoder_hdmi_init and meson_encoder_cvbs_init were not manually removed at mod…

In the Linux kernel, the following vulnerability has been resolved: drm/meson: remove drm bridges at aggregate driver unbind time drm bridges added by meson_encoder_hdmi_init and meson_encoder_cvbs_init were not manually removed at mod…

Twilightlinux · linux_kernelEPSS 0.16%via NVD

Most-affected vendors

By CVEs published in the period.