VulnSea

Weekly digest

Week 44, 2025 (27 Oct – 2 Nov)

A busier-than-usual week with 42 new CVEs (recent average about 32). Of those, 1 critical and 12 high. One arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 5.

42
New CVEs
1
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 42 published.

CVE-2025-11201High· 8.10day
10mo ago

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability

Abyssalmlflow · mlflowEPSS 27%via OSV
CVE-2025-11200High· 8.10day
10mo ago

MLflow Weak Password Requirements Authentication Bypass Vulnerability

MLflow Weak Password Requirements Authentication Bypass Vulnerability

Abyssalmlflow · mlflowEPSS 1.5%via OSV
CVE-2025-40074Critical· 9.8
10mo ago

In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), i…

In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrlim_allow(), ip_defrag() to prevent possible UAF. Change ipmr_prepare_xmit(), ipmr_queue_fwd_xmit(), ip_mr_output(), i…

MidnightLinux · LinuxEPSS 0.43%via NVD
CVE-2025-62727High· 7.5PoC
10mo ago

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Starlette vulnerable to O(n^2) DoS via Range header merging in ``starlette.responses.FileResponse``

Midnightstarlette · starletteEPSS 0.64%via OSV
CVE-2025-40105High· 7.8
10mo ago

vfs: Don't leak disconnected dentries on umount

In the Linux kernel, the following vulnerability has been resolved: vfs: Don't leak disconnected dentries on umount When user calls open_by_handle_at() on some inode that is not cached, we will create disconnected dentry for it. If suc…

TwilightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2025-40064High· 7.8
10mo ago

In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in __pnet_find_base_ndev(). syzbot reported use-after-free of net_device in __pnet_find_base_ndev(), which was called during connect()

In the Linux kernel, the following vulnerability has been resolved: smc: Fix use-after-free in __pnet_find_base_ndev(). syzbot reported use-after-free of net_device in __pnet_find_base_ndev(), which was called during connect(). [0] sm…

TwilightEPSS 0.14%via NVD
CVE-2025-40054High· 7.8
10mo ago

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF issue in f2fs_merge_page_bio() As JY reported in bugzilla [1], Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 pc :…

In the Linux kernel, the following vulnerability has been resolved: f2fs: fix UAF issue in f2fs_merge_page_bio() As JY reported in bugzilla [1], Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 pc :…

TwilightEPSS 0.15%via NVD
CVE-2025-6176High· 7.5
10mo ago

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Scrapy is vulnerable to a denial of service (DoS) attack due to flaws in brotli decompression implementation

Twilightbrotli · brotliEPSS 0.50%via OSV
CVE-2025-61385High
11mo ago

pg8000 SQL injection vulnerability via a specially crafted Python list input

pg8000 SQL injection vulnerability via a specially crafted Python list input

Twilightpg8000 · pg8000EPSS 0.34%via OSV
CVE-2025-62231High· 7.3
10mo ago

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value …

TwilightEPSS 0.28%via NVD
CVE-2025-62230High· 7.3
10mo ago

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup

A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free conditio…

TwilightEPSS 0.26%via NVD
CVE-2025-64104High· 7.3
10mo ago

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

LangGraph SQLite Checkpoint Filter Key SQL Injection POC for SqliteStore

Twilightlanggraph-checkpoint-sqlite · langgraph-checkpoint-sqliteEPSS 0.18%via OSV

Most-affected vendors

By CVEs published in the period.