Google Security Advisories · May 2025 — Google Security Advisories
259 advisories 173 CVEs 23 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2025-05. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 23 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2025-30397

GoogleExploitedCISA KEV listedCRITICAL2025-05-13

Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

CVEs:CVE-2025-30397

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_11_24h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
windows_server_2025 affected microsoft
Upstream advisory

CVE-2025-32706

GoogleExploitedCISA KEV listedHIGH2025-05-13

Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVEs:CVE-2025-32706

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_11_24h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
windows_server_2025 affected microsoft
Upstream advisory

CVE-2025-32709

GoogleExploitedCISA KEV listedHIGH2025-05-13

Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

CVEs:CVE-2025-32709

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_11_24h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
windows_server_2025 affected microsoft
Upstream advisory

CVE-2025-30400

GoogleExploitedCISA KEV listedHIGH2025-05-13

Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

CVEs:CVE-2025-30400

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_11_24h2 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
windows_server_2025 affected microsoft
Upstream advisory

CVE-2025-32701

GoogleExploitedCISA KEV listedHIGH2025-05-13

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

CVEs:CVE-2025-32701

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1809 affected microsoft
windows_10_21h2 affected microsoft
windows_10_22h2 affected microsoft
windows_11_22h2 affected microsoft
windows_11_23h2 affected microsoft
windows_11_24h2 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
windows_server_2022 affected microsoft
windows_server_2022_23h2 affected microsoft
windows_server_2025 affected microsoft
Upstream advisory

MGASA-2025-0159

Open SourceExploitedVulnCheck KEV listedCRITICAL2025-05-23

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:9 chromium-browser-stable
Upstream advisory

openSUSE-SU-2025:15143-1

Open SourceExploitedVulnCheck KEV listed2025-05-21

chromedriver-136.0.7103.113-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

DSA-5920-1

Open SourceExploitedVulnCheck KEV listed2025-05-15

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

GHSA-vxhm-55mv-5fhx

Open SourceExploitedVulnCheck KEV listedCRITICAL2025-05-14

GHSA-vxhm-55mv-5fhx

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2025-4664

GoogleExploitedVulnCheck KEV listed2025-05-14

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-4664

Upstream advisory

CVE-2025-4664

GoogleExploitedVulnCheck KEV listedCRITICAL2025-05-14

Insufficient policy enforcement in Loader in Google Chrome prior to 136.0.7103.113 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-4664

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2025-4664

Open SourceExploitedVulnCheck KEV listedCRITICAL2025-05-14

DEBIAN-CVE-2025-4664

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

MINI-pm5g-pqrw-7hq9

Open SourceActive exploitation (sightings)2025-05-29

MINI-pm5g-pqrw-7hq9

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-m4qc-pc8f-gf27

Open SourceActive exploitation (sightings)2025-05-29

MINI-m4qc-pc8f-gf27

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

CVE-2025-29825

Open SourceActive exploitation (sightings)MEDIUM2025-05-01

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

CVEs:CVE-2025-29825

Affected products

ProductStatusVendorPackageEcosystem
edge_chromium affected microsoft
Upstream advisory

ASB-A-400286977

GoogleActive exploitation (sightings)2025-05-01

ASB-A-400286977

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

DSA-5914-1

Open SourceActive exploitation (sightings)2025-05-01

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2025-48938

Open SourceActive exploitation (sightings)CRITICAL2025-05-30

DEBIAN-CVE-2025-48938

Affected products

ProductStatusVendorPackageEcosystem
golang-github-cli-go-gh affected Debian:12 golang-github-cli-go-gh
golang-github-cli-go-gh affected Debian:13 golang-github-cli-go-gh
golang-github-cli-go-gh affected Debian:14 golang-github-cli-go-gh
golang-github-cli-go-gh-v2 affected Debian:13 golang-github-cli-go-gh-v2
golang-github-cli-go-gh-v2 affected Debian:14 golang-github-cli-go-gh-v2
Upstream advisory

GO-2025-3695

Open SourceActive exploitation (sightings)HIGH2025-05-22

Ollama Server Vulnerable to Denial of Service (DoS) Attack in github.com/ollama/ollama

Affected products

ProductStatusVendorPackageEcosystem
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
mods affected wolfi mods
mods affected chainguard mods
ollama-fips affected chainguard ollama-fips
ollama/ollama affected github.com github.com/ollama/ollama
Upstream advisory

GHSA-wrh5-cmwx-q2qr

GoogleActive exploitation (sightings)HIGH2025-05-16

Ollama Server Vulnerable to Denial of Service (DoS) Attack

Affected products

ProductStatusVendorPackageEcosystem
ollama/ollama affected github.com github.com/ollama/ollama
Upstream advisory

GHSA-wrh5-cmwx-q2qr

Open SourceActive exploitation (sightings)HIGH2025-05-16

Ollama Server Vulnerable to Denial of Service (DoS) Attack

Affected products

ProductStatusVendorPackageEcosystem
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
mods affected chainguard mods
mods affected wolfi mods
ollama-fips affected chainguard ollama-fips
ollama/ollama affected github.com github.com/ollama/ollama
Upstream advisory

DEBIAN-CVE-2025-3757

Open SourceActive exploitation (sightings)CRITICAL2025-05-13

DEBIAN-CVE-2025-3757

Affected products

ProductStatusVendorPackageEcosystem
golang-github-openpubkey-openpubkey affected Debian:13 golang-github-openpubkey-openpubkey
golang-github-openpubkey-openpubkey affected Debian:14 golang-github-openpubkey-openpubkey
Upstream advisory

ASB-A-391928904

GoogleActive exploitation (sightings)2025-05-01

ASB-A-391928904

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2024-12679

GoogleActive exploitation (sightings)MEDIUM2025-05-15

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...

CVEs:CVE-2024-12679

Affected products

ProductStatusVendorPackageEcosystem
google_website_translator affected prisna
Upstream advisory

CVE-2024-12680

GoogleActive exploitation (sightings)MEDIUM2025-05-15

The Prisna GWT WordPress plugin before 1.4.14 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed...

CVEs:CVE-2024-12680

Affected products

ProductStatusVendorPackageEcosystem
google_website_translator affected prisna
Upstream advisory

CVE-2025-4600

GoogleActive exploitation (sightings)HIGH2025-05-15

A request smuggling vulnerability existed in the Google Cloud Classic Application Load Balancer due to improper handling of chunked-encoded HTTP requests. This allowed attackers to craft requests that could be misinterpreted by backend servers. The iss...

CVEs:CVE-2025-4600

Affected products

ProductStatusVendorPackageEcosystem
application_load_balancer affected google
Upstream advisory

CVE-2025-0649

GoogleActive exploitation (sightings)2025-05-06

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

CVEs:CVE-2025-0649

Upstream advisory

CVE-2025-0649

Open SourceActive exploitation (sightings)HIGH2025-05-06

Incorrect JSON input stringification in Google's Tensorflow serving versions up to 2.18.0 allows for potentially unbounded recursion leading to server crash.

CVEs:CVE-2025-0649

Affected products

ProductStatusVendorPackageEcosystem
tensorflow_serving affected google
Upstream advisory

ASB-A-381276124

GoogleActive exploitation (sightings)2025-05-01

ASB-A-381276124

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-381274694

GoogleActive exploitation (sightings)2025-05-01

ASB-A-381274694

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-382314359

GoogleActive exploitation (sightings)2025-05-01

ASB-A-382314359

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-383349630

GoogleActive exploitation (sightings)2025-05-01

ASB-A-383349630

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-20963

Open SourceActive exploitation (sightings)HIGH2025-05-06

Out-of-bounds write in memory initialization in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2025-20963

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20964

Open SourceActive exploitation (sightings)HIGH2025-05-06

Out-of-bounds write in parsing media files in libsavsvc.so prior to SMR May-2025 Release 1 allows local attackers to write out-of-bounds memory.

CVEs:CVE-2025-20964

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

ASB-A-391932683

GoogleActive exploitation (sightings)2025-05-01

ASB-A-391932683

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-380438039

GoogleActive exploitation (sightings)HIGH2025-05-01

ASB-A-380438039

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-1079

GoogleActive exploitation (sightings)CRITICAL2025-05-12

Client RCE on macOS and Linux via improper symbolic link resolution in Google Web Designer's preview feature

CVEs:CVE-2025-1079

Affected products

ProductStatusVendorPackageEcosystem
web_designer affected google
Upstream advisory

ASB-A-383191754

GoogleActive exploitation (sightings)2025-05-01

ASB-A-383191754

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

ASB-A-385657784

GoogleActive exploitation (sightings)2025-05-01

ASB-A-385657784

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-2509

GoogleActive exploitation (sightings)HIGH2025-05-06

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bou...

CVEs:CVE-2025-2509

Affected products

ProductStatusVendorPackageEcosystem
chrome_os affected google
Upstream advisory

CVE-2025-2509

GoogleActive exploitation (sightings)2025-05-06

Out-of-Bounds Read in Virglrenderer in ChromeOS 16093.57.0 allows a malicious guest VM to achieve arbitrary address access within the crosvm sandboxed process, potentially leading to VM escape via crafted vertex elements data triggering an out-of-bounds read in util_format_description.

CVEs:CVE-2025-2509

Upstream advisory

CVE-2025-27700

Open SourceActive exploitation (sightings)HIGH2025-05-06

There is a possible bypass of carrier restrictions due to an unusual root cause. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-27700

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-49739

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In MMapVAccess of pmr_os.c, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-49739

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-369911749

GoogleActive exploitation (sightings)HIGH2025-05-01

ASB-A-369911749

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-330507809

GoogleActive exploitation (sightings)NONE2025-05-01

PUB-A-330507809

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-26428

Open SourceActive exploitation (sightings)LOW2025-05-05

In startLockTaskMode of LockTaskController.java, there is a possible lock screen bypass due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is needed for...

CVEs:CVE-2025-26428

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-0077

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In multiple functions of UserController.java, there is a possible lock screen bypass due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-0077

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-56193

Open SourceActive exploitation (sightings)MEDIUM2025-05-06

There is a possible disclosure of Bluetooth adapter details due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2024-56193

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-27701

Open SourceActive exploitation (sightings)HIGH2025-05-06

In the function process_crypto_cmd, the values of ptrs[i] can be potentially equal to NULL which is valid value after calling slice_map_array(). Later this values will be derefenced without prior NULL check, which can lead to local Temporary DoS or OOB...

CVEs:CVE-2025-27701

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

ASB-A-394100273

GoogleActive exploitation (sightings)2025-05-01

ASB-A-394100273

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

ASB-A-394100476

GoogleActive exploitation (sightings)2025-05-01

ASB-A-394100476

Affected products

ProductStatusVendorPackageEcosystem
:linux_kernel:Qualcomm affected Android :linux_kernel:Qualcomm
Upstream advisory

PUB-A-238299155

GoogleActive exploitation (sightings)MEDIUM2025-05-01

PUB-A-238299155

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

PUB-A-384814655

GoogleActive exploitation (sightings)HIGH2025-05-01

PUB-A-384814655

Affected products

ProductStatusVendorPackageEcosystem
:unknown: affected Android :unknown:
Upstream advisory

CVE-2025-22425

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In onCreate of InstallStart.java, there is a possible permissions bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2025-22425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26421

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In multiple locations, there is a possible lock screen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2025-26421

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26424

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In multiple functions of VpnManager.java, there is a possible cross-user data leak due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2025-26424

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26425

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In multiple functions of RoleService.java, there is a possible permission squatting vulnerability due to a logic error in the code. This could lead to local escalation of privilege on versions of Android where android.permission.MANAGE_DEFAULT_APPLICAT...

CVEs:CVE-2025-26425

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2023-35657

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In bta_av_config_ind of bta_av_aact.cc, there is a possible out of bounds read due to type confusion. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVEs:CVE-2023-35657

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26423

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In validateIpConfiguration of WifiConfigurationUtil.java, there is a possible way to trigger a permanent DoS due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interactio...

CVEs:CVE-2025-26423

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26422

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In dump of WindowManagerService.java, there is a possible way of running dumpsys without the required permission due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User in...

CVEs:CVE-2025-26422

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26444

Open SourceActive exploitation (sightings)HIGH2025-05-05

In onHandleForceStop of VoiceInteractionManagerService.java, there is a bug that could cause the system to incorrectly revert to the default assistant application when a user-selected assistant is forcibly stopped due to a logic error in the code. This...

CVEs:CVE-2025-26444

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26420

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In multiple functions of GrantPermissionsActivity.java , there is a possible way to trick the user into granting the incorrect permission due to permission overload. This could lead to local escalation of privilege with no additional execution privileg...

CVEs:CVE-2025-26420

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26436

Open SourceActive exploitation (sightings)HIGH2025-05-05

In clearAllowBgActivityStarts of PendingIntentRecord.java, there is a possible way for an application to launch an activity from the background due to BAL Bypass. This could lead to local escalation of privilege with no additional execution privileges ...

CVEs:CVE-2025-26436

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26440

Open SourceActive exploitation (sightings)HIGH2025-05-05

In multiple functions of CameraService.cpp, there is a possible way to use the camera from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2025-26440

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-20665

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In devinfo, there is a possible information disclosure due to a missing SELinux policy. This could lead to local information disclosure of device identifier with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2025-20665

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-20668

Open SourceActive exploitation (sightings)HIGH2025-05-05

In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: A...

CVEs:CVE-2025-20668

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-20979

Open SourceActive exploitation (sightings)HIGH2025-05-07

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to execute arbitrary code.

CVEs:CVE-2025-20979

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-20671

Open SourceActive exploitation (sightings)HIGH2025-05-05

In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALP...

CVEs:CVE-2025-20671

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26430

Open SourceActive exploitation (sightings)HIGH2025-05-05

In getDestinationForApp of SpaAppBridgeActivity, there is a possible cross-user file reveal due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2025-26430

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26435

Open SourceActive exploitation (sightings)HIGH2025-05-05

In updateState of ContentProtectionTogglePreferenceController.java, there is a possible way for a secondary user to disable the primary user's deceptive app scanning setting due to a logic error in the code. This could lead to local escalation of privi...

CVEs:CVE-2025-26435

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26442

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In onCreate of NotificationAccessConfirmationActivity.java, there is a possible incorrect verification of proper intent filters in NLS due to a logic error in the code. This could lead to local information disclosure with no additional execution privil...

CVEs:CVE-2025-26442

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26429

Open SourceActive exploitation (sightings)MEDIUM2025-05-05

In collectOps of AppOpsService.java, there is a possible way to cause permanent DoS due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2025-26429

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-20980

Open SourceActive exploitation (sightings)HIGH2025-05-07

Out-of-bounds write in libsavscmn prior to Android 15 allows local attackers to cause memory corruption.

CVEs:CVE-2025-20980

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2025:15075-1

Open SourcePoC exploit2025-05-12

golang-github-prometheus-node_exporter-1.9.1-3.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-node_exporter affected openSUSE:Tumbleweed golang-github-prometheus-node_exporter
Upstream advisory

MINI-vjp8-rq2q-hm9c

Open SourcePoC exploit2025-05-29

MINI-vjp8-rq2q-hm9c

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-v2v9-qc6q-3h55

Open SourcePoC exploit2025-05-29

MINI-v2v9-qc6q-3h55

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

DSA-5929-1

Open SourcePoC exploit2025-05-29

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

GHSA-c82m-4wjj-w8fw

Open SourcePoC exploitCRITICAL2025-05-27

GHSA-c82m-4wjj-w8fw

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2025-5280

GooglePoC exploitCRITICAL2025-05-27

Out of bounds write in V8 in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-5280

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2025-5280

Open SourcePoC exploitCRITICAL2025-05-27

DEBIAN-CVE-2025-5280

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CLSA-2025-1748002217

Open SourcePoC exploit2025-05-23

golang: Fix of CVE-2024-24790

Affected products

ProductStatusVendorPackageEcosystem
golang affected TuxCare:AlmaLinux:9.2 golang
golang-bin affected TuxCare:AlmaLinux:9.2 golang-bin
golang-docs affected TuxCare:AlmaLinux:9.2 golang-docs
golang-misc affected TuxCare:AlmaLinux:9.2 golang-misc
golang-race affected TuxCare:AlmaLinux:9.2 golang-race
golang-src affected TuxCare:AlmaLinux:9.2 golang-src
golang-tests affected TuxCare:AlmaLinux:9.2 golang-tests
Upstream advisory

RLSA-2024:4237

Open SourcePoC exploitHIGH2025-05-07

Moderate: go-toolset security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Rocky Linux:8 delve
golang affected Rocky Linux:8 golang
go-toolset affected Rocky Linux:8 go-toolset
Upstream advisory

MINI-jj63-c5j8-2fqv

Open SourcePoC exploit2025-05-29

MINI-jj63-c5j8-2fqv

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-4q7g-6mcj-x68c

Open SourcePoC exploit2025-05-29

MINI-4q7g-6mcj-x68c

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

GHSA-5rjg-fvgr-3xxf

GooglePoC exploitCRITICAL2025-05-19

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

Affected products

ProductStatusVendorPackageEcosystem
setuptools affected PyPI setuptools
Upstream advisory

GHSA-5rjg-fvgr-3xxf

Open SourcePoC exploitCRITICAL2025-05-19

setuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File Write

Affected products

ProductStatusVendorPackageEcosystem
ansible-operator affected chainguard ansible-operator
ansible-operator-fips affected chainguard ansible-operator-fips
aws-cli-2 affected chainguard aws-cli-2
aws-cli-2 affected wolfi aws-cli-2
awx affected chainguard awx
azure-functions-host affected chainguard azure-functions-host
checkov affected chainguard checkov
checkov affected wolfi checkov
dask-gateway affected wolfi dask-gateway
dask-gateway affected chainguard dask-gateway
datadog-agent affected wolfi datadog-agent
datadog-agent affected chainguard datadog-agent
datadog-agent-7.71 affected chainguard datadog-agent-7.71
datadog-agent-7.72 affected wolfi datadog-agent-7.72
datadog-agent-7.72 affected chainguard datadog-agent-7.72
datadog-agent-7.73 affected wolfi datadog-agent-7.73
datadog-agent-7.73 affected chainguard datadog-agent-7.73
datadog-agent-7.74 affected chainguard datadog-agent-7.74
datadog-agent-7.74 affected wolfi datadog-agent-7.74
datadog-agent-7.76 affected chainguard datadog-agent-7.76
datadog-agent-7.76 affected wolfi datadog-agent-7.76
datadog-agent-7.77 affected wolfi datadog-agent-7.77
datadog-agent-7.77 affected chainguard datadog-agent-7.77
datadog-agent-7.78 affected wolfi datadog-agent-7.78
datadog-agent-7.78 affected chainguard datadog-agent-7.78
datadog-agent-7.79 affected chainguard datadog-agent-7.79
datadog-agent-7.79 affected wolfi datadog-agent-7.79
datadog-agent-7.80 affected chainguard datadog-agent-7.80
datadog-agent-7.80 affected wolfi datadog-agent-7.80
datadog-agent-fips affected chainguard datadog-agent-fips
datadog-agent-fips-7.71 affected chainguard datadog-agent-fips-7.71
datadog-agent-fips-7.72 affected chainguard datadog-agent-fips-7.72
datadog-agent-fips-7.73 affected chainguard datadog-agent-fips-7.73
datadog-agent-fips-7.74 affected chainguard datadog-agent-fips-7.74
datadog-agent-fips-7.76 affected chainguard datadog-agent-fips-7.76
datadog-agent-fips-7.77 affected chainguard datadog-agent-fips-7.77
datadog-agent-fips-7.78 affected chainguard datadog-agent-fips-7.78
datadog-agent-fips-7.79 affected chainguard datadog-agent-fips-7.79
datadog-agent-fips-7.80 affected chainguard datadog-agent-fips-7.80
emissary affected chainguard emissary
emissary affected wolfi emissary
graalvm-25 affected chainguard graalvm-25
jwt-tool affected chainguard jwt-tool
jwt-tool affected wolfi jwt-tool
kserve affected wolfi kserve
kserve affected chainguard kserve
kubeflow-katib affected chainguard kubeflow-katib
kubeflow-katib affected wolfi kubeflow-katib
localstack affected chainguard localstack
nemo affected chainguard nemo
nvidia-nsight-compute-13.1 affected chainguard nvidia-nsight-compute-13.1
nvidia-nsight-compute-13.2 affected chainguard nvidia-nsight-compute-13.2
nvidia-nsight-compute-13.3 affected chainguard nvidia-nsight-compute-13.3
pgadmin4 affected chainguard pgadmin4
pgadmin4-fips affected chainguard pgadmin4-fips
py3.10-pytorch-cuda-12.3 affected chainguard py3.10-pytorch-cuda-12.3
py3.10-vllm-cuda-11.8 affected chainguard py3.10-vllm-cuda-11.8
py3.11-pytorch-cuda-11.8 affected chainguard py3.11-pytorch-cuda-11.8
py3.11-pytorch-cuda-12.3 affected chainguard py3.11-pytorch-cuda-12.3
py3-cassandra-medusa affected chainguard py3-cassandra-medusa
py3-cassandra-medusa affected wolfi py3-cassandra-medusa
py3-hashin affected chainguard py3-hashin
py3-pipenv affected wolfi py3-pipenv
py3-pipenv affected chainguard py3-pipenv
pypy-3.10 affected wolfi pypy-3.10
pypy-3.10 affected chainguard pypy-3.10
pypy-3.11 affected chainguard pypy-3.11
pypy-3.11 affected wolfi pypy-3.11
request-1276 affected chainguard request-1276
setuptools affected PyPI setuptools
setuptools affected PyPI setuptools
setuptools affected PyPI
spamcheck affected chainguard spamcheck
superset affected chainguard superset
superset affected wolfi superset
tensorflow-cpu-jupyter affected chainguard tensorflow-cpu-jupyter
tensorflow-cpu-jupyter affected wolfi tensorflow-cpu-jupyter
tensorflow-gpu-jupyter affected chainguard tensorflow-gpu-jupyter
text-generation-inference affected chainguard text-generation-inference
wazuh-manager affected chainguard wazuh-manager
wazuh-manager-fips affected chainguard wazuh-manager-fips
Upstream advisory

RHSA-2025:7138

Open SourcePoC exploitMEDIUM2025-05-14

Red Hat Security Advisory: protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected Red Hat:enterprise_linux:9::appstream protobuf
protobuf affected Red Hat:enterprise_linux:9::crb protobuf
protobuf-compiler affected Red Hat:enterprise_linux:9::appstream protobuf-compiler
protobuf-compiler affected Red Hat:enterprise_linux:9::crb protobuf-compiler
protobuf-compiler-debuginfo affected Red Hat:enterprise_linux:9::appstream protobuf-compiler-debuginfo
protobuf-compiler-debuginfo affected Red Hat:enterprise_linux:9::crb protobuf-compiler-debuginfo
protobuf-debuginfo affected Red Hat:enterprise_linux:9::crb protobuf-debuginfo
protobuf-debuginfo affected Red Hat:enterprise_linux:9::appstream protobuf-debuginfo
protobuf-debugsource affected Red Hat:enterprise_linux:9::appstream protobuf-debugsource
protobuf-debugsource affected Red Hat:enterprise_linux:9::crb protobuf-debugsource
protobuf-devel affected Red Hat:enterprise_linux:9::appstream protobuf-devel
protobuf-devel affected Red Hat:enterprise_linux:9::crb protobuf-devel
protobuf-lite affected Red Hat:enterprise_linux:9::appstream protobuf-lite
protobuf-lite affected Red Hat:enterprise_linux:9::crb protobuf-lite
protobuf-lite-debuginfo affected Red Hat:enterprise_linux:9::crb protobuf-lite-debuginfo
protobuf-lite-debuginfo affected Red Hat:enterprise_linux:9::appstream protobuf-lite-debuginfo
protobuf-lite-devel affected Red Hat:enterprise_linux:9::appstream protobuf-lite-devel
protobuf-lite-devel affected Red Hat:enterprise_linux:9::crb protobuf-lite-devel
python3-protobuf affected Red Hat:enterprise_linux:9::appstream python3-protobuf
python3-protobuf affected Red Hat:enterprise_linux:9::crb python3-protobuf
Upstream advisory

ALSA-2025:7138

Open SourcePoC exploitHIGH2025-05-13

Moderate: protobuf security update

Affected products

ProductStatusVendorPackageEcosystem
protobuf affected AlmaLinux:9 protobuf
protobuf-compiler affected AlmaLinux:9 protobuf-compiler
protobuf-devel affected AlmaLinux:9 protobuf-devel
protobuf-lite affected AlmaLinux:9 protobuf-lite
protobuf-lite-devel affected AlmaLinux:9 protobuf-lite-devel
python3-protobuf affected AlmaLinux:9 python3-protobuf
Upstream advisory

GO-2025-3645

Open SourcePoC exploit2025-05-05

Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CLSA-2025-1746792031

Open SourcePoC exploit2025-05-09

golang: Fix of 2 CVEs

Affected products

ProductStatusVendorPackageEcosystem
golang affected TuxCare:AlmaLinux:9.2 golang
golang-bin affected TuxCare:AlmaLinux:9.2 golang-bin
golang-docs affected TuxCare:AlmaLinux:9.2 golang-docs
golang-misc affected TuxCare:AlmaLinux:9.2 golang-misc
golang-race affected TuxCare:AlmaLinux:9.2 golang-race
golang-src affected TuxCare:AlmaLinux:9.2 golang-src
golang-tests affected TuxCare:AlmaLinux:9.2 golang-tests
Upstream advisory

CLSA-2025-1747058667

Open SourcePoC exploit2025-05-12

golang: Fix of 2 CVEs

Affected products

ProductStatusVendorPackageEcosystem
golang affected TuxCare:AlmaLinux:9.2 golang
golang-bin affected TuxCare:AlmaLinux:9.2 golang-bin
golang-docs affected TuxCare:AlmaLinux:9.2 golang-docs
golang-misc affected TuxCare:AlmaLinux:9.2 golang-misc
golang-race affected TuxCare:AlmaLinux:9.2 golang-race
golang-src affected TuxCare:AlmaLinux:9.2 golang-src
golang-tests affected TuxCare:AlmaLinux:9.2 golang-tests
Upstream advisory

RHSA-2025:7484

Open SourcePoC exploitHIGH2025-05-13

Red Hat Security Advisory: gvisor-tap-vsock security update

Affected products

ProductStatusVendorPackageEcosystem
gvisor-tap-vsock affected Red Hat:enterprise_linux:10.0 gvisor-tap-vsock
gvisor-tap-vsock-debuginfo affected Red Hat:enterprise_linux:10.0 gvisor-tap-vsock-debuginfo
gvisor-tap-vsock-debugsource affected Red Hat:enterprise_linux:10.0 gvisor-tap-vsock-debugsource
gvisor-tap-vsock-gvforwarder affected Red Hat:enterprise_linux:10.0 gvisor-tap-vsock-gvforwarder
gvisor-tap-vsock-gvforwarder-debuginfo affected Red Hat:enterprise_linux:10.0 gvisor-tap-vsock-gvforwarder-debuginfo
Upstream advisory

RHSA-2025:7416

Open SourcePoC exploitHIGH2025-05-13

Red Hat Security Advisory: gvisor-tap-vsock security update

Affected products

ProductStatusVendorPackageEcosystem
gvisor-tap-vsock affected Red Hat:enterprise_linux:9::appstream gvisor-tap-vsock
gvisor-tap-vsock-debuginfo affected Red Hat:enterprise_linux:9::appstream gvisor-tap-vsock-debuginfo
gvisor-tap-vsock-debugsource affected Red Hat:enterprise_linux:9::appstream gvisor-tap-vsock-debugsource
gvisor-tap-vsock-gvforwarder affected Red Hat:enterprise_linux:9::appstream gvisor-tap-vsock-gvforwarder
gvisor-tap-vsock-gvforwarder-debuginfo affected Red Hat:enterprise_linux:9::appstream gvisor-tap-vsock-gvforwarder-debuginfo
Upstream advisory

ALSA-2025:7484

Open SourcePoC exploitHIGH2025-05-13

Important: gvisor-tap-vsock security update

Affected products

ProductStatusVendorPackageEcosystem
gvisor-tap-vsock affected AlmaLinux:10 gvisor-tap-vsock
gvisor-tap-vsock-gvforwarder affected AlmaLinux:10 gvisor-tap-vsock-gvforwarder
Upstream advisory

MINI-mqcj-qxjx-327q

Open SourcePoC exploit2025-05-29

MINI-mqcj-qxjx-327q

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

MINI-447h-mrcw-2pw8

Open SourcePoC exploit2025-05-29

MINI-447h-mrcw-2pw8

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

RHSA-2025:7466

Open SourcePoC exploitMEDIUM2025-05-13

Red Hat Security Advisory: delve and golang security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected Red Hat:enterprise_linux:10.0 delve
delve-debuginfo affected Red Hat:enterprise_linux:10.0 delve-debuginfo
delve-debugsource affected Red Hat:enterprise_linux:10.0 delve-debugsource
golang affected Red Hat:enterprise_linux:10.0 golang
golang-bin affected Red Hat:enterprise_linux:10.0 golang-bin
golang-docs affected Red Hat:enterprise_linux:10.0 golang-docs
golang-misc affected Red Hat:enterprise_linux:10.0 golang-misc
golang-src affected Red Hat:enterprise_linux:10.0 golang-src
golang-tests affected Red Hat:enterprise_linux:10.0 golang-tests
go-toolset affected Red Hat:enterprise_linux:10.0 go-toolset
Upstream advisory

ALSA-2025:7466

Open SourcePoC exploit2025-05-13

Moderate: delve and golang security update

Affected products

ProductStatusVendorPackageEcosystem
delve affected AlmaLinux:10 delve
golang affected AlmaLinux:10 golang
golang-bin affected AlmaLinux:10 golang-bin
golang-docs affected AlmaLinux:10 golang-docs
golang-misc affected AlmaLinux:10 golang-misc
golang-src affected AlmaLinux:10 golang-src
golang-tests affected AlmaLinux:10 golang-tests
go-toolset affected AlmaLinux:10 go-toolset
Upstream advisory

CLSA-2025-1747854434

Open SourcePoC exploit2025-05-21

Fix CVE(s): CVE-2024-9287

Affected products

ProductStatusVendorPackageEcosystem
idle-python3.6 affected TuxCare:Ubuntu:18.04 idle-python3.6
libpython3.6 affected TuxCare:Ubuntu:18.04 libpython3.6
libpython3.6-dev affected TuxCare:Ubuntu:18.04 libpython3.6-dev
libpython3.6-minimal affected TuxCare:Ubuntu:18.04 libpython3.6-minimal
libpython3.6-stdlib affected TuxCare:Ubuntu:18.04 libpython3.6-stdlib
libpython3.6-testsuite affected TuxCare:Ubuntu:18.04 libpython3.6-testsuite
python3.6 affected TuxCare:Ubuntu:18.04 python3.6
python3.6-dev affected TuxCare:Ubuntu:18.04 python3.6-dev
python3.6-doc affected TuxCare:Ubuntu:18.04 python3.6-doc
python3.6-examples affected TuxCare:Ubuntu:18.04 python3.6-examples
python3.6-minimal affected TuxCare:Ubuntu:18.04 python3.6-minimal
python3.6-venv affected TuxCare:Ubuntu:18.04 python3.6-venv
Upstream advisory

openSUSE-SU-2025:0145-1

Open SourcePoC exploitCRITICAL2025-05-06

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP6 chromium
chromium affected openSUSE:Leap 15.6 chromium
Upstream advisory

openSUSE-SU-2025:15051-1

Open SourcePoC exploit2025-05-04

chromedriver-136.0.7103.59-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

MINI-w8g2-284f-8w8j

Open SourcePoC exploit2025-05-29

MINI-w8g2-284f-8w8j

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

MINI-62h9-wrjp-79x7

Open SourcePoC exploit2025-05-29

MINI-62h9-wrjp-79x7

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

openSUSE-SU-2025:0148-1

Open SourcePoC exploitCRITICAL2025-05-09

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.6 chromium
chromium affected SUSE:Package Hub 15 SP6 chromium
Upstream advisory

openSUSE-SU-2025:15073-1

Open SourcePoC exploit2025-05-09

chromedriver-136.0.7103.92-1.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Tumbleweed chromium
Upstream advisory

GHSA-2vq3-r375-cjhg

Open SourcePoC exploitCRITICAL2025-05-07

GHSA-2vq3-r375-cjhg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DSA-5916-1

Open SourcePoC exploit2025-05-07

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
Upstream advisory

DEBIAN-CVE-2025-4372

Open SourcePoC exploitCRITICAL2025-05-06

DEBIAN-CVE-2025-4372

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-4372

GooglePoC exploit2025-05-06

Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-4372

Upstream advisory

CVE-2025-4372

GooglePoC exploitCRITICAL2025-05-06

Use after free in WebAudio in Google Chrome prior to 136.0.7103.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-4372

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-v9xg-688g-r69h

Open SourcePoC exploitCRITICAL2025-05-05

GHSA-v9xg-688g-r69h

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-4096

Open SourcePoC exploitCRITICAL2025-05-05

DEBIAN-CVE-2025-4096

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CLSA-2025-1748626881

Open SourcePoC exploit2025-05-30

golang: Fix of 2 CVEs

Affected products

ProductStatusVendorPackageEcosystem
golang affected TuxCare:AlmaLinux:9.2 golang
golang-bin affected TuxCare:AlmaLinux:9.2 golang-bin
golang-docs affected TuxCare:AlmaLinux:9.2 golang-docs
golang-misc affected TuxCare:AlmaLinux:9.2 golang-misc
golang-race affected TuxCare:AlmaLinux:9.2 golang-race
golang-src affected TuxCare:AlmaLinux:9.2 golang-src
golang-tests affected TuxCare:AlmaLinux:9.2 golang-tests
Upstream advisory

openSUSE-SU-2025:15178-1

Open SourcePoC exploit2025-05-30

golang-github-prometheus-alertmanager-0.28.1-2.1 on GA media

Affected products

ProductStatusVendorPackageEcosystem
golang-github-prometheus-alertmanager affected openSUSE:Tumbleweed golang-github-prometheus-alertmanager
Upstream advisory

MINI-rpfg-vjph-9fr8

Open SourcePoC exploit2025-05-29

MINI-rpfg-vjph-9fr8

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-qpj9-jjr4-rv3j

Open SourcePoC exploit2025-05-29

MINI-qpj9-jjr4-rv3j

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

DLA-4151-1

Open SourcePoC exploitMEDIUM2025-05-01

golang-github-gorilla-csrf - security update

Affected products

ProductStatusVendorPackageEcosystem
golang-github-gorilla-csrf affected Debian:11 golang-github-gorilla-csrf
Upstream advisory

CVE-2025-22873

GooglePoC exploitLOW2025-05-06

It was possible to improperly access the parent directory of an os.Root by opening a filename ending in "../". For example, Root.Open("../") would open the parent directory of the Root. This escape only permits opening the parent directory itself, not ...

CVEs:CVE-2025-22873

Affected products

ProductStatusVendorPackageEcosystem
go affected golang
Upstream advisory

GHSA-w87c-v4h6-r3wj

Open SourceCoalition ESS < 30%CRITICAL2025-05-27

GHSA-w87c-v4h6-r3wj

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-5063

Open SourceCoalition ESS < 30%CRITICAL2025-05-27

DEBIAN-CVE-2025-5063

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-5063

GoogleCoalition ESS < 30%CRITICAL2025-05-21

Use after free in Compositing in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVEs:CVE-2025-5063

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

MINI-87q2-pfw9-w663

Open SourceCoalition ESS < 30%2025-05-29

MINI-87q2-pfw9-w663

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

GO-2025-3678

Open SourceCoalition ESS < 30%2025-05-15

Ring: some aes functions may panic when overflow checking is enabled in ring in github.com/briansmith/ring

Affected products

ProductStatusVendorPackageEcosystem
atuin affected chainguard atuin
atuin affected wolfi atuin
briansmith/ring affected github.com github.com/briansmith/ring
buck2 affected wolfi buck2
buck2 affected chainguard buck2
cargo-audit affected chainguard cargo-audit
cargo-audit affected wolfi cargo-audit
deno affected chainguard deno
deno affected wolfi deno
fnm affected chainguard fnm
kdash affected wolfi kdash
kdash affected chainguard kdash
linkerd2-proxy affected chainguard linkerd2-proxy
linkerd2-proxy affected wolfi linkerd2-proxy
linkerd-extension-init affected chainguard linkerd-extension-init
linkerd-extension-init affected wolfi linkerd-extension-init
lychee affected chainguard lychee
lychee affected wolfi lychee
ntpd-rs affected wolfi ntpd-rs
ntpd-rs affected chainguard ntpd-rs
nushell affected chainguard nushell
nushell affected wolfi nushell
oranda affected wolfi oranda
oranda affected chainguard oranda
parseable affected chainguard parseable
parseable affected wolfi parseable
pixi affected chainguard pixi
pixi affected wolfi pixi
qdrant affected wolfi qdrant
qdrant affected chainguard qdrant
rustls-ffi affected wolfi rustls-ffi
rustls-ffi affected chainguard rustls-ffi
rustup affected wolfi rustup
rustup affected chainguard rustup
rye affected chainguard rye
rye affected wolfi rye
samply affected chainguard samply
samply affected wolfi samply
sccache affected wolfi sccache
sccache affected chainguard sccache
sdp-k8s-injector affected wolfi sdp-k8s-injector
sdp-k8s-injector affected chainguard sdp-k8s-injector
shadowsocks-rust affected wolfi shadowsocks-rust
shadowsocks-rust affected chainguard shadowsocks-rust
sqlx affected chainguard sqlx
sqlx affected wolfi sqlx
tealdeer affected wolfi tealdeer
tealdeer affected chainguard tealdeer
uv affected wolfi uv
uv affected chainguard uv
wadm affected chainguard wadm
wadm affected wolfi wadm
wash affected chainguard wash
wash affected wolfi wash
wasmcloud affected chainguard wasmcloud
wasmcloud affected wolfi wasmcloud
wasm-pack affected wolfi wasm-pack
wasm-pack affected chainguard wasm-pack
wasmtime affected wolfi wasmtime
wasmtime affected chainguard wasmtime
xh affected wolfi xh
xh affected chainguard xh
zed affected wolfi zed
zed affected chainguard zed
zizmor affected wolfi zizmor
zizmor affected chainguard zizmor
zola affected wolfi zola
zola affected chainguard zola
ztunnel-1.25 affected chainguard ztunnel-1.25
ztunnel-fips-1.25 affected chainguard ztunnel-fips-1.25
Upstream advisory

GHSA-7cx3-6m66-7c5m

Open SourceCoalition ESS < 30%HIGH2025-05-16

Tornado vulnerable to excessive logging caused by malformed multipart form data

Affected products

ProductStatusVendorPackageEcosystem
airflow affected wolfi airflow
airflow affected chainguard airflow
airflow-3 affected chainguard airflow-3
airflow-3 affected wolfi airflow-3
airflow-core affected chainguard airflow-core
dask-kubernetes affected wolfi dask-kubernetes
dask-kubernetes affected chainguard dask-kubernetes
grafana-oncall affected chainguard grafana-oncall
grafana-oncall affected wolfi grafana-oncall
jupyter-base-notebook affected wolfi jupyter-base-notebook
jupyter-base-notebook affected chainguard jupyter-base-notebook
kubeflow-pipelines-visualization-server affected chainguard kubeflow-pipelines-visualization-server
kubeflow-pipelines-visualization-server affected wolfi kubeflow-pipelines-visualization-server
tensorflow-cpu-jupyter affected wolfi tensorflow-cpu-jupyter
tensorflow-cpu-jupyter affected chainguard tensorflow-cpu-jupyter
tornado affected PyPI tornado
tornado affected PyPI tornado
Upstream advisory

GHSA-7cx3-6m66-7c5m

GoogleCoalition ESS < 30%HIGH2025-05-16

Tornado vulnerable to excessive logging caused by malformed multipart form data

Affected products

ProductStatusVendorPackageEcosystem
tornado affected PyPI tornado
Upstream advisory

GHSA-j84v-78j2-55gh

Open SourceCoalition ESS < 30%CRITICAL2025-05-27

GHSA-j84v-78j2-55gh

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
firefox affected chainguard firefox
firefox affected wolfi firefox
firefox-esr affected chainguard firefox-esr
Upstream advisory

CVE-2025-5283

GoogleCoalition ESS < 30%CRITICAL2025-05-27

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-5283

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-5283

GoogleCoalition ESS < 30%2025-05-27

Use after free in libvpx in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-5283

Upstream advisory

DEBIAN-CVE-2025-5283

Open SourceCoalition ESS < 30%CRITICAL2025-05-27

DEBIAN-CVE-2025-5283

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
firefox-esr affected Debian:14 firefox-esr
libvpx affected Debian:11 libvpx
libvpx affected Debian:12 libvpx
libvpx affected Debian:13 libvpx
libvpx affected Debian:14 libvpx
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

GO-2025-3689

Open SourceCoalition ESS < 30%2025-05-15

Ollama Divide by Zero Vulnerability in github.com/ollama/ollama

Affected products

ProductStatusVendorPackageEcosystem
k8sgpt affected chainguard k8sgpt
k8sgpt affected wolfi k8sgpt
mods affected wolfi mods
mods affected chainguard mods
ollama-fips affected chainguard ollama-fips
ollama/ollama affected github.com github.com/ollama/ollama
Upstream advisory

GHSA-2pgc-776h-4jhr

Open SourceCoalition ESS < 30%CRITICAL2025-05-05

GHSA-2pgc-776h-4jhr

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-4052

Open SourceCoalition ESS < 30%CRITICAL2025-05-05

DEBIAN-CVE-2025-4052

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

MINI-gvp4-jhm3-qrwf

Open SourceCoalition ESS < 30%2025-05-29

MINI-gvp4-jhm3-qrwf

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-c6h4-mvx2-c89h

Open SourceCoalition ESS < 30%2025-05-29

MINI-c6h4-mvx2-c89h

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

GHSA-vvqw-r3vv-46ph

Open SourceCoalition ESS < 30%HIGH2025-05-05

GHSA-vvqw-r3vv-46ph

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-4050

Open SourceCoalition ESS < 30%HIGH2025-05-05

DEBIAN-CVE-2025-4050

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-78m4-4wrg-v443

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

GHSA-78m4-4wrg-v443

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-5065

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

DEBIAN-CVE-2025-5065

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-5065

GoogleCoalition ESS < 30%MEDIUM2025-05-21

Inappropriate implementation in FileSystemAccess API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-5065

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-g3gr-c6vj-5j9j

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

GHSA-g3gr-c6vj-5j9j

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-5066

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

DEBIAN-CVE-2025-5066

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-5066

GoogleCoalition ESS < 30%MEDIUM2025-05-21

Inappropriate implementation in Messages in Google Chrome on Android prior to 137.0.7151.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Me...

CVEs:CVE-2025-5066

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-36504

Open SourceCoalition ESS < 30%CRITICAL2025-05-07

When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVEs:CVE-2025-36504

Affected products

ProductStatusVendorPackageEcosystem
big-ip_access_policy_manager affected f5
big-ip_advanced_firewall_manager affected f5
big-ip_advanced_web_application_firewall affected f5
big-ip_analytics affected f5
big-ip_application_acceleration_manager affected f5
big-ip_application_security_manager affected f5
big-ip_application_visibility_and_reporting affected f5
big-ip_automation_toolchain affected f5
big-ip_carrier-grade_nat affected f5
big-ip_container_ingress_services affected f5
big-ip_ddos_hybrid_defender affected f5
big-ip_domain_name_system affected f5
big-ip_edge_gateway affected f5
big-ip_fraud_protection_service affected f5
big-ip_global_traffic_manager affected f5
big-ip_link_controller affected f5
big-ip_local_traffic_manager affected f5
big-ip_next_central_manager affected f5
big-ip_next_cloud-native_network_functions affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
big-ip_policy_enforcement_manager affected f5
big-ip_ssl_orchestrator affected f5
big-ip_webaccelerator affected f5
big-ip_websafe affected f5
Upstream advisory

CVE-2025-36557

Open SourceCoalition ESS < 30%CRITICAL2025-05-07

When an HTTP profile with the Enforce RFC Compliance option is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (E...

CVEs:CVE-2025-36557

Affected products

ProductStatusVendorPackageEcosystem
big-ip_access_policy_manager affected f5
big-ip_advanced_firewall_manager affected f5
big-ip_analytics affected f5
big-ip_application_acceleration_manager affected f5
big-ip_application_security_manager affected f5
big-ip_domain_name_system affected f5
big-ip_fraud_protection_service affected f5
big-ip_global_traffic_manager affected f5
big-ip_link_controller affected f5
big-ip_local_traffic_manager affected f5
big-ip_next_cloud-native_network_functions affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
big-ip_policy_enforcement_manager affected f5
Upstream advisory

CVE-2025-41399

Open SourceCoalition ESS < 30%CRITICAL2025-05-07

When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not...

CVEs:CVE-2025-41399

Affected products

ProductStatusVendorPackageEcosystem
big-ip_access_policy_manager affected f5
big-ip_advanced_firewall_manager affected f5
big-ip_advanced_web_application_firewall affected f5
big-ip_analytics affected f5
big-ip_application_acceleration_manager affected f5
big-ip_application_security_manager affected f5
big-ip_application_visibility_and_reporting affected f5
big-ip_automation_toolchain affected f5
big-ip_carrier-grade_nat affected f5
big-ip_container_ingress_services affected f5
big-ip_ddos_hybrid_defender affected f5
big-ip_domain_name_system affected f5
big-ip_edge_gateway affected f5
big-ip_fraud_protection_service affected f5
big-ip_global_traffic_manager affected f5
big-ip_link_controller affected f5
big-ip_local_traffic_manager affected f5
big-ip_next_central_manager affected f5
big-ip_next_cloud-native_network_functions affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
big-ip_policy_enforcement_manager affected f5
big-ip_ssl_orchestrator affected f5
big-ip_webaccelerator affected f5
big-ip_websafe affected f5
Upstream advisory

CVE-2025-41414

Open SourceCoalition ESS < 30%HIGH2025-05-07

When HTTP/2 client and server profile is configured on a virtual server, undisclosed requests can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVEs:CVE-2025-41414

Affected products

ProductStatusVendorPackageEcosystem
big-ip_access_policy_manager affected f5
big-ip_advanced_firewall_manager affected f5
big-ip_advanced_web_application_firewall affected f5
big-ip_analytics affected f5
big-ip_application_acceleration_manager affected f5
big-ip_application_security_manager affected f5
big-ip_application_visibility_and_reporting affected f5
big-ip_automation_toolchain affected f5
big-ip_carrier-grade_nat affected f5
big-ip_container_ingress_services affected f5
big-ip_ddos_hybrid_defender affected f5
big-ip_domain_name_system affected f5
big-ip_edge_gateway affected f5
big-ip_fraud_protection_service affected f5
big-ip_global_traffic_manager affected f5
big-ip_link_controller affected f5
big-ip_local_traffic_manager affected f5
big-ip_next_cloud-native_network_functions affected f5
big-ip_next_service_proxy_for_kubernetes affected f5
big-ip_policy_enforcement_manager affected f5
big-ip_ssl_orchestrator affected f5
big-ip_webaccelerator affected f5
big-ip_websafe affected f5
Upstream advisory

CVE-2025-4609

GoogleCoalition ESS < 30%CRITICAL2025-05-14

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVEs:CVE-2025-4609

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-4609

GoogleCoalition ESS < 30%2025-05-14

Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVEs:CVE-2025-4609

Upstream advisory

GHSA-vcfj-m4g8-j8jv

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

GHSA-vcfj-m4g8-j8jv

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-5067

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

DEBIAN-CVE-2025-5067

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-5067

GoogleCoalition ESS < 30%MEDIUM2025-05-21

Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2025-5067

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-5067

GoogleCoalition ESS < 30%2025-05-21

Inappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVEs:CVE-2025-5067

Upstream advisory

GHSA-4g9c-v26v-gp27

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

GHSA-4g9c-v26v-gp27

Affected products

ProductStatusVendorPackageEcosystem
chromium affected wolfi chromium
chromium affected chainguard chromium
Upstream advisory

DEBIAN-CVE-2025-5064

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

DEBIAN-CVE-2025-5064

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-5064

GoogleCoalition ESS < 30%MEDIUM2025-05-21

Inappropriate implementation in Background Fetch API in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-5064

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2025-26438

Open SourceCoalition ESS < 30%HIGH2025-05-05

In smp_process_secure_connection_oob_data of smp_act.cc, there is a possible way to bypass SMP authentication due to Incorrect implementation of a protocol. This could lead to remote escalation of privilege with no additional execution privileges neede...

CVEs:CVE-2025-26438

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2024-11109

GoogleCoalition ESS < 30%MEDIUM2025-05-15

The WP Google Review Slider WordPress plugin before 15.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ...

CVEs:CVE-2024-11109

Affected products

ProductStatusVendorPackageEcosystem
wp_google_review_slider affected ljapps
Upstream advisory

GHSA-2xf7-h82x-mhhg

Open SourceCoalition ESS < 30%MEDIUM2025-05-05

GHSA-2xf7-h82x-mhhg

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

DEBIAN-CVE-2025-4051

Open SourceCoalition ESS < 30%MEDIUM2025-05-05

DEBIAN-CVE-2025-4051

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

GHSA-hqjf-gj2q-64ch

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

GHSA-hqjf-gj2q-64ch

Affected products

ProductStatusVendorPackageEcosystem
chromium affected chainguard chromium
chromium affected wolfi chromium
Upstream advisory

CVE-2025-5281

GoogleCoalition ESS < 30%MEDIUM2025-05-27

Inappropriate implementation in BFCache in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to potentially obtain user information via a crafted HTML page. (Chromium security severity: Medium)

CVEs:CVE-2025-5281

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2025-5281

Open SourceCoalition ESS < 30%MEDIUM2025-05-27

DEBIAN-CVE-2025-5281

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2025-20937

Open SourceCoalition ESS < 30%HIGH2025-05-06

Out-of-bounds write in Keymaster trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVEs:CVE-2025-20937

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20954

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Use of implicit intent for sensitive communication in EnrichedCall prior to SMR May-2025 Release 1 allows local attackers to access sensitive information. User interaction is required for triggering this vulnerability.

CVEs:CVE-2025-20954

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20955

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Improper Export of Android Application Components in NotificationHistoryImageProvider prior to SMR May-2025 Release 1 allows local attackers to access notification images.

CVEs:CVE-2025-20955

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20962

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Improper handling of insufficient permission in SpenGesture service prior to SMR May-2025 Release 1 allows local attackers to track the S Pen position.

CVEs:CVE-2025-20962

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20957

Open SourceCoalition ESS < 30%HIGH2025-05-06

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch arbitrary activities with SmartManagerCN privilege.

CVEs:CVE-2025-20957

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20953

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Improper access control in SmartManagerCN prior to SMR May-2025 Release 1 allows local attackers to launch activities within SmartManagerCN.

CVEs:CVE-2025-20953

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20961

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Improper handling of insufficient permission or privileges in sepunion service prior to SMR May-2025 Release 1 allows local privileged attackers to access files with system privilege.

CVEs:CVE-2025-20961

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20959

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Use of implicit intent for sensitive communication in Wi-Fi P2P service prior to SMR May-2025 Release 1 allows local attackers to access sensitive information.

CVEs:CVE-2025-20959

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20960

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Improper handling of insufficient permission in CocktailBarService prior to SMR May-2025 Release 1 allows local attackers to use the privileged api.

CVEs:CVE-2025-20960

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-20958

Open SourceCoalition ESS < 30%MEDIUM2025-05-06

Improper verification of intent by broadcast receiver in UnifiedWFC prior to SMR May-2025 Release 1 allows local attackers to manipulate VoWiFi related behaviors.

CVEs:CVE-2025-20958

Affected products

ProductStatusVendorPackageEcosystem
android affected samsung
Upstream advisory

CVE-2025-26427

Open SourceCoalition ESS < 30%MEDIUM2025-05-05

In multiple locations, there is a possible Android/data access due to a path traversal error. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVEs:CVE-2025-26427

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2025-26426

Open SourceCoalition ESS < 30%MEDIUM2025-05-05

In BroadcastController.java of registerReceiverWithFeatureTraced, there is a possible way to receive broadcasts meant for the "android" package due to improper input validation. This could lead to local escalation of privilege with no additional execut...

CVEs:CVE-2025-26426

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

MINI-pr7h-3c9f-cq4r

Open SourceEPSS <= 49%2025-05-29

MINI-pr7h-3c9f-cq4r

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

MINI-hrvr-c39m-vc8r

Open SourceEPSS <= 49%2025-05-29

MINI-hrvr-c39m-vc8r

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-gggg-9w3f-294q

Open SourceEPSS <= 49%2025-05-29

MINI-gggg-9w3f-294q

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

MINI-35fx-43h7-4xmc

Open SourceEPSS <= 49%2025-05-29

MINI-35fx-43h7-4xmc

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

MINI-g966-998x-7g6c

Open SourceEPSS <= 49%2025-05-29

MINI-g966-998x-7g6c

Affected products

ProductStatusVendorPackageEcosystem
kube-apiserver-1.32 affected MinimOS kube-apiserver-1.32
kube-controller-manager-1.32 affected MinimOS kube-controller-manager-1.32
kubectl-1.32 affected MinimOS kubectl-1.32
kubectl-1.32-advanced-compat affected MinimOS kubectl-1.32-advanced-compat
kube-proxy-1.32 affected MinimOS kube-proxy-1.32
kubernetes-1.32 affected MinimOS kubernetes-1.32
kube-scheduler-1.32 affected MinimOS kube-scheduler-1.32
Upstream advisory

MINI-8wjq-7ggm-hq8f

Open SourceEPSS <= 49%2025-05-29

MINI-8wjq-7ggm-hq8f

Affected products

ProductStatusVendorPackageEcosystem
kubectl-1.31 affected MinimOS kubectl-1.31
kubectl-1.31-advanced-compat affected MinimOS kubectl-1.31-advanced-compat
kubernetes-1.31 affected MinimOS kubernetes-1.31
Upstream advisory

CVE-2023-2334

GoogleEPSS <= 49%MEDIUM2025-05-15

The edd-google-sheet-connector-pro WordPress plugin before 1.4, Easy Digital Downloads Google Sheet Connector WordPress plugin before 1.6.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin chan...

CVEs:CVE-2023-2334

Affected products

ProductStatusVendorPackageEcosystem
easy_digital_downloads_google_sheet_connector affected westerndeal
edd_gsheetconnector affected gsheetconnector
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.