Weekly digest
Week 48, 2025 (24–30 Nov)
33 new CVEs this week, in line with the recent average. Of those, 4 critical and 11 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. trytond was the most-affected vendor with 3.
New this week, ranked by depth score
The 12 that matter most of the 33 published.
CVE-2025-62593CriticalCISA KEVPoCRay is an AI compute engine
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…
CVE-2025-50433Critical· 9.8PoCAn issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.
An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.
CVE-2025-61168Critical· 9.8An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
CVE-2025-12758High· 7.5PoCVersions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…
Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode variation selectors (\uFE0F, \uFE0E)…
CVE-2025-34351CriticalRay's New Token Authentication is Disabled By Default
Ray's New Token Authentication is Disabled By Default
CVE-2025-62703High· 8.8Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
Fugue is Vulnerable to Remote Code Execution by Pickle Deserialization via FlaskRPCServer
CVE-2025-13609High· 8.2A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID)
A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using a different Trusted Platform Module (TPM) device but claiming an existing agent's unique identifier (UUID). This acti…
CVE-2025-13601High· 7.7A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function
A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would ne…
CVE-2025-65965HighGrype has a credential disclosure vulnerability in its JSON output
Grype has a credential disclosure vulnerability in its JSON output
CVE-2025-13502High· 7.5A flaw was found in WebKitGTK and WPE WebKit
A flaw was found in WebKitGTK and WPE WebKit. This vulnerability allows an out-of-bounds read and integer underflow, leading to a UIProcess crash (DoS) via a crafted payload to the GLib remote inspector server.
CVE-2025-64761HighOpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
CVE-2025-13792High· 7.3A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97
A security flaw has been discovered in Qualitor up to 8.20.104/8.24.97. Affected by this vulnerability is the function eval of the file /html/st/stdeslocamento/request/getResumo.php. Performing a manipulation of the argument passageiros …
Most-affected vendors
By CVEs published in the period.