Cyber Threat Digest – 2025-08-29
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-7775 — Citrix NetScaler Memory Overflow Vulnerability — Citrix NetScaler (Added: 2025-08-26) — Details
- CVE-2025-48384 — Git Link Following Vulnerability — Git Git (Added: 2025-08-25) — Details
- CVE-2024-8068 — Citrix Session Recording Improper Privilege Management Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
- CVE-2024-8069 — Citrix Session Recording Deserialization of Untrusted Data Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
- CVE-2025-43300 — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability — Apple iOS, iPadOS, and macOS (Added: 2025-08-21) — Details
- CVE-2025-54948 — Trend Micro Apex One OS Command Injection Vulnerability — Trend Micro Apex One (Added: 2025-08-18) — Details
- CVE-2025-8876 — N-able N-Central Command Injection Vulnerability — N-able N-Central (Added: 2025-08-13) — Details
- CVE-2025-8875 — N-able N-Central Insecure Deserialization Vulnerability — N-able N-Central (Added: 2025-08-13) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2024-49790 — IBM Watson Studio on Cloud Pak for Data 4.0 and 5.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the… MEDIUM 5.4 — Details
- CVE-2025-51967 — A Reflected Cross-site Scripting (XSS) vulnerability exists in the themeSet.php file of ProjectsAndPrograms School Management System 1.0. The application fails to sanitize user-sup… MEDIUM 6.1 — Details
- CVE-2025-51968 — A SQL Injection vulnerability exists in the action.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The application fails to properly sanitize user-supplied input in… MEDIUM 6.5 — Details
- CVE-2025-51969 — A SQL Injection vulnerability exists in the product.php page of PuneethReddyHC Online Shopping System Advanced 1.0. This flaw is present in the product_id GET parameter, which is n… MEDIUM 6.5 — Details
- CVE-2025-51971 — A reflected Cross-Site Scripting (XSS) vulnerability exists in register.php of PuneethReddyHC Online Shopping System Advanced 1.0. Unsanitized user input in the f_name parameter is… MEDIUM 5.4 — Details
- CVE-2025-51972 — A SQL Injection vulnerability exists in the login.php of PuneethReddyHC Online Shopping System Advanced 1.0 due to improper sanitization of user-supplied input in the keyword POST … MEDIUM 6.5 — Details
📰 Security News
Top headlines from trusted sources.
- Google warns Salesloft breach impacted some Workspace accounts
— Thu, 28 Aug 2025 22:09:24 GMT - US targets North Korean IT worker army with new sanctions
— Thu, 28 Aug 2025 19:11:23 GMT - Google shares workarounds for auth failures on ChromeOS devices
— Thu, 28 Aug 2025 18:30:07 GMT - Malware devs abuse Anthropic's Claude AI to build ransomware
— Thu, 28 Aug 2025 17:08:08 GMT - Microsoft Word will save your files to the cloud by default
— Thu, 28 Aug 2025 17:00:28 GMT - Passwordstate dev urges users to patch auth bypass vulnerability
— Thu, 28 Aug 2025 16:16:20 GMT
Comments
Post a Comment