VulnSea

Weekly digest

Week 43, 2025 (20–26 Oct)

20 new CVEs this week, in line with the recent average. Of those, 1 critical and 6 high. 4 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. ascertia was the most-affected vendor with 3.

20
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 20 published.

CVE-2025-56224High· 8.1PoC
11mo ago

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.

Midnightascertia · signinghubEPSS 0.39%via NVD
CVE-2025-56447Critical· 9.8
11mo ago

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.

MidnightEPSS 0.27%via NVD
CVE-2025-56223High· 7.5PoC
11mo ago

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.

Midnightascertia · signinghubEPSS 0.46%via NVD
CVE-2025-56219High· 7.1PoC
11mo ago

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting

Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user acco…

Midnightascertia · signinghubEPSS 0.32%via NVD
CVE-2025-11844Medium· 5.4PoC
11mo ago

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function

Twilightsmolagents · smolagentsEPSS 0.26%via OSV
CVE-2025-12105High· 7.5
11mo ago

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications

A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an …

TwilightEPSS 0.43%via NVD
CVE-2025-62611High
11mo ago

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server

Twilightaiomysql · aiomysqlEPSS 0.36%via OSV
CVE-2025-8709High· 7.3
11mo ago

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

LangGraph's SQLite store implementation has a SQL Injection Vulnerability

Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.17%via OSV
CVE-2025-57848Medium· 6.4
11mo ago

A container privilege escalation flaw was found in certain Container-native Virtualization images

A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an atta…

SunlitEPSS 0.18%via NVD
CVE-2025-60419Medium· 6.2
11mo ago

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.

An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.

SunlitEPSS 0.13%via NVD
CVE-2025-62607Medium· 5.3
11mo ago

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL

Sunlitnautobot-ssot · nautobot-ssotEPSS 0.27%via OSV
CVE-2025-62708Medium
11mo ago

pypdf can exhaust RAM via manipulated LZWDecode streams

pypdf can exhaust RAM via manipulated LZWDecode streams

Sunlitpypdf · pypdfEPSS 0.41%via OSV

Most-affected vendors

By CVEs published in the period.