VulnSea

Weekly digest

Week 49, 2025 (1–7 Dec)

A heavy week: 86 new CVEs, well above the recent average of about 31. Of those, 10 critical and 22 high. 10 arrived with exploitation evidence or public exploit code already attached. CISA added one CVE to the Known Exploited Vulnerabilities catalog. entrust was the most-affected vendor with 13.

86
New CVEs
10
Critical
1
KEV additions
0
Records changed

Added to CISA KEV

Confirmed exploitation in the wild — federal remediation deadlines attach to these.

New this week, ranked by depth score

The 12 that matter most of the 86 published.

CVE-2025-55182Critical· 10.0CISA KEVPoC
9mo ago

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

Hadalfacebook · reactEPSS 100%via NVD
CVE-2025-34291High· 8.8CISA KEVPoC
9mo ago

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a …

Abyssallangflow · langflowEPSS 84%via NVD
CVE-2025-57199High· 8.8PoC
9mo ago

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary

AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injection vulnerability in the NetFailDetectD binary. This vulnerability allows attackers to execute arbitrary commands vi…

Midnightavtech · dgm1104_firmwareEPSS 3.3%via NVD
CVE-2025-29268Critical· 9.8
9mo ago

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.

Midnightallnet · all-rut22gw_firmwareEPSS 8.5%via NVD
CVE-2025-40261Critical· 9.8
9mo ago

nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl()

In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to complete before returning, and an error c…

MidnightLinux · LinuxEPSS 0.56%via CVEORG
CVE-2025-29269Critical· 9.8
9mo ago

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

Midnightallnet · all-rut22gw_firmwareEPSS 2.0%via NVD
CVE-2025-65896Critical· 9.8
9mo ago

asyncmy is vulnerable to SQL injection via crafted dict keys

asyncmy is vulnerable to SQL injection via crafted dict keys

Midnightasyncmy · asyncmyEPSS 0.43%via OSV
CVE-2025-59695Critical· 9.8
9mo ago

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication)

Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). T…

Midnightentrust · nshield_5c_firmwareEPSS 0.67%via NVD
CVE-2025-59693Critical· 9.8
9mo ago

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate pri…

The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate pri…

Midnightentrust · nshield_5c_firmwareEPSS 0.90%via NVD
CVE-2025-12060Critical· 9.8
9mo ago

Keras Directory Traversal Vulnerability

Keras Directory Traversal Vulnerability

Midnightkeras · kerasEPSS 0.59%via OSV
CVE-2025-65945High· 7.5PoC
9mo ago

auth0/node-jws is a JSON Web Signature implementation for Node.js

auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under specific conditi…

Midnightauth0 · node-jwsEPSS 0.21%via NVD
CVE-2025-65637HighPoC
9mo ago

Logrus is vulnerable to DoS when using Entry.Writer()

Logrus is vulnerable to DoS when using Entry.Writer()

Midnightsirupsen · github.com/sirupsen/logrusEPSS 0.63%via OSV

Most-affected vendors

By CVEs published in the period.