Weekly digest
Week 45, 2025 (3–9 Nov)
28 new CVEs this week, in line with the recent average. Severity skewed high: 2 critical and 12 high, 50% of the total. 8 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. apple was the most-affected vendor with 5.
Added to CISA KEV
Confirmed exploitation in the wild — federal remediation deadlines attach to these.
New this week, ranked by depth score
The 12 that matter most of the 28 published.
CVE-2025-10230Critical· 10.0PoCA flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserte…
CVE-2023-43000High· 8.8CISA KEVPoCA use-after-free issue was addressed with improved memory management
A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to …
CVE-2025-64495High· 8.7PoCOpen WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
CVE-2025-64512High· 8.6PoCArbitrary Code Execution in pdfminer.six via Crafted PDF Input
Arbitrary Code Execution in pdfminer.six via Crafted PDF Input
CVE-2025-70559High· 7.8PoCInsecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
Insecure Deserialization (pickle) in pdfminer.six CMap Loader — Local Privesc
CVE-2025-60787High· 7.2PoCmotionEye vulnerable to RCE via unsanitized motion config parameter
motionEye vulnerable to RCE via unsanitized motion config parameter
CVE-2022-50589Critical· 9.8SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality
SuiteCRM versions prior to 7.12.6 contain a SQL injection vulnerability within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute…
CVE-2025-64458High· 7.5PoCDjango has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-43433High· 8.8The issue was addressed with improved memory handling
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. Processing maliciously crafted w…
CVE-2025-64184High· 8.8Dosage vulnerable to a Directory Traversal through crafted HTTP responses
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
CVE-2025-64496High· 7.3Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
CVE-2025-64324High· 7.7KubeVirt Vulnerable to Arbitrary Host File Read and Write
KubeVirt Vulnerable to Arbitrary Host File Read and Write
Most-affected vendors
By CVEs published in the period.