Weekly digest
Week 42, 2025 (13–19 Oct)
26 new CVEs this week, in line with the recent average. Of those, 5 critical and 7 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 5.
New this week, ranked by depth score
The 12 that matter most of the 26 published.
CVE-2025-39964High· 7.8CISA KEVPoCIn the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…
CVE-2025-56218Critical· 9.8PoCAn arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a crafted PDF file.
CVE-2025-34282Critical· 9.1PoCThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature
ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload Gallery feature. An attacker can upload a malicious SVG file that references a remote URL. If the server processes th…
CVE-2025-34267Critical· 9.9Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) w…
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) w…
CVE-2025-11849Critical· 9.3Mammoth is vulnerable to Directory Traversal
Mammoth is vulnerable to Directory Traversal
CVE-2025-54603Critical· 9.0An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.
An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users.
CVE-2025-48044High· 8.6Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.
Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 3.6.3 before 3.7.1.
CVE-2025-39978High· 7.8octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix potential use after free in otx2_tc_add_flow() This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node" and then dereferences it on …
CVE-2025-39977High· 7.8futex: Prevent use-after-free during requeue-PI
In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI syzbot managed to trigger the following race: T1 T2 futex_wait_requeue_pi() fute…
CVE-2025-59043High· 7.5OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
CVE-2025-62172HighHome Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
CVE-2025-7707High· 7.1llama-index has Insecure Temporary File
llama-index has Insecure Temporary File
Most-affected vendors
By CVEs published in the period.