Cyber Threat Digest – 2025-08-28

πŸ”₯ Known Exploited Vulnerabilities (CISA KEV)

8 exploited vulns of note.

  • CVE-2025-7775 — Citrix NetScaler Memory Overflow Vulnerability — Citrix NetScaler (Added: 2025-08-26) — Details
  • CVE-2025-48384 — Git Link Following Vulnerability — Git Git (Added: 2025-08-25) — Details
  • CVE-2024-8068 — Citrix Session Recording Improper Privilege Management Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
  • CVE-2024-8069 — Citrix Session Recording Deserialization of Untrusted Data Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
  • CVE-2025-43300 — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability — Apple iOS, iPadOS, and macOS (Added: 2025-08-21) — Details
  • CVE-2025-54948 — Trend Micro Apex One OS Command Injection Vulnerability — Trend Micro Apex One (Added: 2025-08-18) — Details
  • CVE-2025-8876 — N-able N-Central Command Injection Vulnerability — N-able N-Central (Added: 2025-08-13) — Details
  • CVE-2025-8875 — N-able N-Central Insecure Deserialization Vulnerability — N-able N-Central (Added: 2025-08-13) — Details

⚠️ Recent CVEs (NVD)

Latest CVEs with CVSS badges.

  • CVE-2018-25115 — Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi en… CRITICAL 10.0Details
  • CVE-2023-7307 — Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the… HIGH 8.7Details
  • CVE-2023-7308 — SecGate3600, a network firewall product developed by NSFOCUS, contains a sensitive information disclosure vulnerability in the /cgi-bin/authUser/authManageSet.cgi endpoint. The aff… HIGH 8.7Details
  • CVE-2023-7309 — A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting … CRITICAL 10.0Details
  • CVE-2024-13979 — A SQL injection vulnerability exists in the St. Joe ERP system ("εœ£δΉ”ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requ… CRITICAL 9.3Details
  • CVE-2024-13980 — H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling… CRITICAL 10.0Details

πŸ“° Security News

Top headlines from trusted sources.

Comments

Popular posts from this blog

Cyber Threat Digest – 2025-09-05

Cyber Threat Digest – 2025-09-06