📅 Weekly CVE Roundup

November 3 - November 9, 2025

21 Total CVEs
0 Critical
6 High
14 Medium

🔴 Critical & High Severity Vulnerabilities

These are the most dangerous vulnerabilities disclosed this week. Prioritize patching these.

🏢 Most Affected Vendors

Salesforce 6 CVEs
Kagilum 1 CVEs
Opensource Socialnetwork 1 CVEs
Workdo 1 CVEs
Guominjim 1 CVEs

🐛 Common Vulnerability Types

CWE-94 5 occurrences
CWE-79 4 occurrences
CWE-400 2 occurrences
CWE-732 2 occurrences
CWE-20 1 occurrences

📋 All CVEs This Week

CVE-2025-60785 8.8

A remote code execution vulnerability in iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code through a...

CVE-2025-20727 8.1

This vulnerability is a heap buffer overflow in MediaTek modem firmware that allows remote code execution when a device ...

CVE-2025-63551 7.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in MetInfo CMS that can be triggered via XML Exter...

CVE-2025-63560 7.5

A vulnerability in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder firmware allows remote attackers to cause d...

CVE-2025-63441 7.3

Open Source Social Network (OSSN) 8.6 contains a reflected cross-site scripting vulnerability in the administrator frien...

CVE-2025-64328 7.2

FreePBX Endpoint Manager's filestore module contains a post-authentication command injection vulnerability in the SSH te...

CVE-2025-52662 6.9

This vulnerability in Nuxt DevTools allows cross-site scripting (XSS) attacks that could extract authentication tokens u...

CVE-2025-59392 6.8

This vulnerability allows physical attackers to reset the admin password on Elspec G5 devices by inserting a USB drive w...

CVE-2025-64320 6.5

This vulnerability allows attackers to inject malicious code into Salesforce Agentforce Vibes Extension's LLM prompting ...

CVE-2025-10875 6.5

This vulnerability allows attackers to inject malicious code through improperly sanitized input used for LLM prompting i...

CVE-2025-63294 6.5

CVE-2025-63294 is an insecure permissions vulnerability in WorkDo HRM SaaS HR and Payroll Tool 8.1 that allows authentic...

CVE-2025-63686 6.5

This CVE describes an arbitrary file download vulnerability in GuoMinJim PersonManage software. Attackers can download a...

CVE-2025-61431 6.1

A reflected cross-site scripting (XSS) vulnerability in Zucchetti ZMaintenance Infinity and Infinity Zucchetti allows at...

CVE-2025-60753 5.5

A vulnerability in libarchive's bsdtar allows attackers to cause denial of service through unbounded memory allocation w...

CVE-2025-64319 5.3

This vulnerability allows attackers to manipulate writeable configuration files in Salesforce Mulesoft Anypoint Code Bui...

CVE-2025-64321 5.3

This vulnerability allows attackers to manipulate configuration files through improper input neutralization in Salesforc...

CVE-2025-64322 5.3

This vulnerability allows attackers to manipulate configuration files due to incorrect permission assignments in Salesfo...

CVE-2025-60925 5.3

codeshare v1.0.0 contains an information leakage vulnerability that allows unauthorized access to users' full collaborat...

CVE-2025-64318 5.3

This vulnerability allows attackers to manipulate LLM prompts to write malicious content to configuration files in Sales...

CVE-2025-64174 4.8

This stored XSS vulnerability in Magento-lts allows attackers with admin database access or control over admin notificat...

CVE-2025-48985 3.7

This vulnerability in Vercel's AI SDK allows users to bypass filetype whitelists when uploading files, potentially enabl...

📚 Past Roundups