VulnSea

Weekly digest

Week 40, 2025 (29 Sep – 5 Oct)

34 new CVEs this week, in line with the recent average. Of those, 1 critical and 8 high. One arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. linux was the most-affected vendor with 11.

34
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 34 published.

CVE-2025-61882Critical· 9.8CISA KEV0dayPoC
11mo ago

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration)

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated…

Hadaloracle · concurrent_processingEPSS 100%via NVD
CVE-2025-59682High· 8.8⚖ disputed
11mo ago

django: Potential partial directory-traversal via archive.extract() (CVE-2025-59682)

A flaw was found in Django. The django.utils.archive.extract() function, used by startapp --templateand startproject --template, allowed partial directory-traversal via an archive with file paths sharing a common prefix with the target dir…

TwilightRed Hat · Red Hat Ansible Automation Platform 2.5 for RHEL 8EPSS 0.91%via CSAF
CVE-2025-54286High· 8.3
11mo ago

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI

Twilightcanonical · github.com/canonical/lxdEPSS 0.13%via OSV
CVE-2022-50442High· 8.4
11mo ago

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate buffer length while parsing index indx_read is called when we have some NTFS directory operations that need more information from the index buffers.…

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate buffer length while parsing index indx_read is called when we have some NTFS directory operations that need more information from the index buffers.…

Twilightlinux · linux_kernelEPSS 0.17%via NVD
CVE-2022-50507High· 7.8
11mo ago

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate data run offset This adds sanity checks for data run offset

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Validate data run offset This adds sanity checks for data run offset. We should make sure data run offset is legit before trying to unpack them, otherwise we…

Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2025-11234High· 7.5
11mo ago

A flaw was found in QEMU

A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSource is leaked. This can lead to the callback firing later on and triggering a use-after-free in the use of the channel.…

TwilightRed Hat · qemuEPSS 0.86%via NVD
CVE-2025-59681High· 7.1
11mo ago

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7

An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), QuerySet.alias(), QuerySet.aggregate(), and QuerySet.extra() are subject to SQL injection in column aliases, when using a …

Twilightdjangoproject · djangoEPSS 0.63%via NVD
CVE-2025-39901High· 7.1
11mo ago

In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early da…

In the Linux kernel, the following vulnerability has been resolved: i40e: remove read access to debugfs files The 'command' and 'netdev_ops' debugfs files are a legacy debugging interface supported by the i40e driver since its early da…

Twilightlinux · linux_kernelEPSS 0.15%via NVD
CVE-2021-4460High· 7.1
11mo ago

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up doing a shift operation where the number of bits s…

In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix UBSAN shift-out-of-bounds warning If get_num_sdma_queues or get_num_xgmi_sdma_queues is 0, we end up doing a shift operation where the number of bits s…

Twilightlinux · linux_kernelEPSS 0.16%via NVD
CVE-2025-54289Medium· 6.8
11mo ago

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

Canonical LXD Vulnerable to Privilege Escalation via WebSocket Connection Hijacking in Operations API

Sunlitcanonical · github.com/canonical/lxdEPSS 0.21%via OSV
CVE-2025-54293Medium· 6.5
11mo ago

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function

Sunlitcanonical · github.com/canonical/lxdEPSS 0.58%via OSV
CVE-2025-54287Medium· 6.5
11mo ago

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

Canonical LXD Arbitrary File Read via Template Injection in Snapshot Patterns

Sunlitlxc · github.com/lxc/lxdEPSS 0.37%via OSV

Most-affected vendors

By CVEs published in the period.