Weekly digest
Week 43, 2025 (20–26 Oct)
20 new CVEs this week, in line with the recent average. Of those, 1 critical and 6 high. 4 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. ascertia was the most-affected vendor with 3.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 20 published.
CVE-2025-56224High· 8.1PoCA lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
A lack of rate limiting in the One-Time Password (OTP) verification endpoint of SigningHub v8.6.8 allows attackers to bypass verification via a bruteforce attack.
CVE-2025-56447Critical· 9.8TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
CVE-2025-56223High· 7.5PoCA lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.
A lack of rate limiting in the component /Home/UploadStreamDocument of SigningHub v8.6.8 allows attackers to cause a Denial of Service (DoS) via uploading an excessive number of files.
CVE-2025-56219High· 7.1PoCIncorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting
Incorrect access control in SigningHub v8.6.8 allows attackers to arbitrarily add user accounts without any rate limiting. This can lead to a resource exhaustion and a Denial of Service (DoS) when an excessively large number of user acco…
CVE-2025-11844Medium· 5.4PoCHugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function
CVE-2025-12105High· 7.5A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications
A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an …
CVE-2025-62611Highaiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
CVE-2025-8709High· 7.3LangGraph's SQLite store implementation has a SQL Injection Vulnerability
LangGraph's SQLite store implementation has a SQL Injection Vulnerability
CVE-2025-57848Medium· 6.4A container privilege escalation flaw was found in certain Container-native Virtualization images
A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an atta…
CVE-2025-60419Medium· 6.2An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.
An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authenticated attackers to send a crafted IOCTL request to the driver to cause a denial of service.
CVE-2025-62607Medium· 5.3Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
Nautobot Single Source of Truth (SSoT) has an unauthenticated ServiceNow configuration URL
CVE-2025-62708Mediumpypdf can exhaust RAM via manipulated LZWDecode streams
pypdf can exhaust RAM via manipulated LZWDecode streams
Most-affected vendors
By CVEs published in the period.