VulnSea

Weekly digest

Week 47, 2025 (17–23 Nov)

28 new CVEs this week, in line with the recent average. Of those, 2 critical and 7 high. 3 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog.

28
New CVEs
2
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 28 published.

CVE-2025-13223High· 8.8CISA KEVPoC
10mo ago

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Abyssalgoogle · chromeEPSS 5.0%via NVD
CVE-2025-65015Critical
10mo ago

joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads

joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads

Midnightjoserfc · joserfcEPSS 0.41%via OSV
CVE-2025-60455Critical
10mo ago

Modular Max Serve has Unsafe Deserialization vulnerability

Modular Max Serve has Unsafe Deserialization vulnerability

Midnightmodular · modularEPSS 0.31%via OSV
CVE-2025-62164High· 8.8
10mo ago

vLLM deserialization vulnerability leading to DoS and potential RCE

vLLM deserialization vulnerability leading to DoS and potential RCE

Twilightvllm · vllmEPSS 0.89%via OSV
CVE-2025-63892Medium· 6.8PoC
10mo ago

A vulnerability was determined in SourceCodester Student Grades Management System 1.0

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_classroom of the file /classroom.php of the component My Classrooms Management Page. This manipulation of the argument…

Twilightremyandrade · student_grades_management_systemEPSS 0.36%via NVD
CVE-2025-56499Medium· 6.5PoC
10mo ago

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary files with elevated privileges via obtaining the external control key from the config file.

Twilightmetacubex · mihomoEPSS 0.30%via NVD
CVE-2025-61662High· 7.8
10mo ago

A Use-After-Free vulnerability has been discovered in GRUB's gettext module

A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error where the gettext command remains registered in memory after its module is unloaded. An attacker can exploit this condi…

Twilightgnu · grub2EPSS 0.20%via NVD
CVE-2025-65106High
10mo ago

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates

Twilightlangchain-core · langchain-coreEPSS 0.51%via OSV
CVE-2025-25613High· 7.5
10mo ago

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless

FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2.2.0D Build 135103 were discovered to transmit cookies for their web based administrative application containing user…

Twilightfs · s3150-8t2f_firmwareEPSS 0.23%via NVD
CVE-2025-64076High· 7.5
10mo ago

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (s…

Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C extension decoder (source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read (CWE-191, CWE-125): An incorre…

Twilightcbor2 · cbor2EPSS 0.46%via OSV
CVE-2025-65073High· 7.5
10mo ago

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

OpenStack Keystone allows /v3/ec2tokens or /v3/s3tokens request with valid AWS Signature to provide Keystone authorization.

Twilightkeystone · keystoneEPSS 0.23%via OSV
CVE-2025-62426Medium· 6.5
10mo ago

vllm: vLLM vulnerable to DoS via large Chat Completion or Tokenization requests with specially crafted `chat_template_kwargs` (CVE-2025-624…

A vulnerability in vLLM allows an authenticated user to trigger unintended tokenization during chat template processing by supplying crafted chat_template_kwargs to the /v1/chat/completions or /tokenize endpoints. By forcing the server to …

SunlitRed Hat · Red Hat Enterprise Linux AI (RHEL AI)EPSS 0.37%via CSAF

Most-affected vendors

By CVEs published in the period.