VulnSea

Weekly digest

Week 52, 2025 (22–28 Dec)

27 new CVEs this week, in line with the recent average. Of those, 5 critical and 8 high. 3 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. Linux was the most-affected vendor with 6.

27
New CVEs
5
Critical
0
KEV additions
0
Records changed

New this week, ranked by depth score

The 12 that matter most of the 27 published.

CVE-2025-68664Critical· 9.3PoC
9mo ago

langchain-core: LangChain: Arbitrary code execution via serialization injection (CVE-2025-68664)

A flaw was found in LangChain, a framework for building agents and LLM-powered applications. A remote attacker can exploit a serialization injection vulnerability in LangChain's `dumps()` and `dumpd()` functions. This occurs because the fu…

AbyssalRed Hat · Red Hat Ansible Automation Platform 2.5EPSS 43%via CSAF
CVE-2025-65856Critical· 9.8PoC
9mo ago

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams

Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 allows unauthenticated remote attackers to access sensitive device information and live video streams. The ONVIF i…

Abyssalxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.74%via NVD
CVE-2025-67108Critical· 10.0
9mo ago

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure communications and connections.

Midnighteprosima · fast_ddsEPSS 0.31%via NVD
CVE-2025-67288Critical· 10.0
9mo ago

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file

An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a crafted PDF file. NOTE: this is disputed by the Supplier because the responsibility for file validation (as shown in …

Midnightumbraco · umbraco_cmsEPSS 0.55%via NVD
CVE-2025-67289Critical· 9.6
9mo ago

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execute arbitrary code via uploading a crafted XML file.

Midnightfrappe · erpnextEPSS 0.46%via NVD
CVE-2025-65857High· 7.5PoC
9mo ago

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06

An issue was discovered in Xiongmai XM530 IP cameras on firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06. The GetStreamUri exposes RTSP URIs containing hardcoded credentials enabling direct unauthorized video stream access.

Midnightxiongmaitech · xm530v200_x6-weq_8m_firmwareEPSS 0.43%via NVD
CVE-2025-67729High· 8.8
9mo ago

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()

Twilightlmdeploy · lmdeployEPSS 0.60%via OSV
CVE-2025-68939High· 8.2
9mo ago

Gitea allows attackers to add attachments with forbidden file extensions

Gitea allows attackers to add attachments with forbidden file extensions

Twilightgitea · code.gitea.io/giteaEPSS 0.33%via OSV
CVE-2025-68724High· 7.8
9mo ago

crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id

In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id Use check_add_overflow() to guard against potential integer overflows when adding the binary b…

TwilightLinux · LinuxEPSS 0.14%via CVEORG
CVE-2025-68349High· 7.5
9mo ago

NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid

In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Clear NFS_INO_LAYOUTCOMMIT in pnfs_mark_layout_stateid_invalid Fixes a crash when layout is null during this call stack: write_inode -> nfs4_write_ino…

TwilightLinux · LinuxEPSS 0.69%via CVEORG
CVE-2025-65865High· 7.5
9mo ago

An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

An integer overflow in eProsima Fast-DDS v3.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

Twilighteprosima · fast_ddsEPSS 0.40%via NVD
CVE-2025-68337High· 7.5
9mo ago

jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted

In the Linux kernel, the following vulnerability has been resolved: jbd2: avoid bug_on in jbd2_journal_get_create_access() when file system corrupted There's issue when file system corrupted: ------------[ cut here ]------------ kernel…

TwilightLinux · LinuxEPSS 0.54%via CVEORG

Most-affected vendors

By CVEs published in the period.