VulnSea

Weekly digest

Week 46, 2025 (10–16 Nov)

25 new CVEs this week, in line with the recent average. Severity skewed high: 1 critical and 16 high, 68% of the total. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. Linux was the most-affected vendor with 3.

25
New CVEs
1
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 25 published.

CVE-2025-40123High· 7.8PoC
10mo ago

bpf: Enforce expected_attach_type for tailcall compatibility

In the Linux kernel, the following vulnerability has been resolved: bpf: Enforce expected_attach_type for tailcall compatibility Yinhao et al. recently reported: Our fuzzer tool discovered an uninitialized pointer issue in the bpf…

MidnightLinux · LinuxEPSS 0.15%via CVEORG
CVE-2025-56385Critical· 9.8
10mo ago

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint

A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporat…

Midnightwellsky · harmonyEPSS 0.41%via NVD
CVE-2025-2843High· 8.8
10mo ago

A flaw was found in the Observability Operator

A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment of the *Namespace-Scoped* Custom Resource MonitorStack. This issue allows an adversarial Kubernetes Account with onl…

TwilightRed Hat · Cluster Observability Operator 1.3.1EPSS 0.33%via NVD
CVE-2025-59088High· 8.6
10mo ago

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name

If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default, it will query SRV records in the DNS zone matching the requested realm name. This creates a server-side request for…

TwilightEPSS 0.46%via NVD
CVE-2025-60689Medium· 5.4PoC
10mo ago

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz)

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl…

Twilightlinksys · e1200_firmwareEPSS 17%via NVD
CVE-2025-40168High· 8.1
10mo ago

In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). smc_clc_prfx_match() is called from smc_listen_work() and not under RCU nor RTNL. Using sk_dst_get(…

In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in smc_clc_prfx_match(). smc_clc_prfx_match() is called from smc_listen_work() and not under RCU nor RTNL. Using sk_dst_get(…

TwilightEPSS 0.39%via NVD
CVE-2025-40135High· 8.1
10mo ago

ipv6: use RCU in ip6_xmit()

In the Linux kernel, the following vulnerability has been resolved: ipv6: use RCU in ip6_xmit() Use RCU in ip6_xmit() in order to use dst_dev_rcu() to prevent possible UAF.

TwilightLinux · LinuxEPSS 0.55%via CVEORG
CVE-2025-30398High· 8.1
10mo ago

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Missing authorization in Nuance PowerScribe allows an unauthorized attacker to disclose information over a network.

Twilightmicrosoft · nuance_powerscribe_360EPSS 0.79%via NVD
CVE-2025-12967High· 8.0
10mo ago

AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance

AWS Advanced Python Wrapper: Privilege Escalation in Aurora PostgreSQL instance

Twilightaws-advanced-python-wrapper · aws-advanced-python-wrapperEPSS 0.45%via OSV
CVE-2025-40206High· 7.8
10mo ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefmap expressions Referencing a synproxy stateful object from OUTPUT hook causes kernel crash due to infinite recursive …

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefmap expressions Referencing a synproxy stateful object from OUTPUT hook causes kernel crash due to infinite recursive …

TwilightEPSS 0.14%via NVD
CVE-2025-40139High· 7.8
10mo ago

In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). smc_clc_prfx_set() is called during connect() and not under RCU nor RTNL. Using sk_dst_get(sk)->de…

In the Linux kernel, the following vulnerability has been resolved: smc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set(). smc_clc_prfx_set() is called during connect() and not under RCU nor RTNL. Using sk_dst_get(sk)->de…

TwilightEPSS 0.15%via NVD
CVE-2025-12748Medium· 5.5PoC
10mo ago

A flaw was discovered in libvirt in the XML file processing

A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files was performed before the ACL checks. A malicious user with limited permissions could exploit this flaw by submitting a…

TwilightEPSS 0.21%via NVD

Most-affected vendors

By CVEs published in the period.