Did you check the first post of this thread? -> http://www.howtoforge.com/forums/showthread.php?t=47423
There are once again 4 new vulnerability announcements, 2 of them affecting 3.5.x. PMASA-2013-2 is quite interesting. I didn't know that preg_replace() is so easy to exploit. I think I have some homework to do :/ Cf. http://www.phpmyadmin.net/home_page/security/PMASA-2013-2.php