Cyber Threat Digest – 2025-08-31
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-57819 — Sangoma FreePBX Authentication Bypass Vulnerability — Sangoma FreePBX (Added: 2025-08-29) — Details
- CVE-2025-7775 — Citrix NetScaler Memory Overflow Vulnerability — Citrix NetScaler (Added: 2025-08-26) — Details
- CVE-2025-48384 — Git Link Following Vulnerability — Git Git (Added: 2025-08-25) — Details
- CVE-2024-8068 — Citrix Session Recording Improper Privilege Management Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
- CVE-2024-8069 — Citrix Session Recording Deserialization of Untrusted Data Vulnerability — Citrix Session Recording (Added: 2025-08-25) — Details
- CVE-2025-43300 — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability — Apple iOS, iPadOS, and macOS (Added: 2025-08-21) — Details
- CVE-2025-54948 — Trend Micro Apex One OS Command Injection Vulnerability — Trend Micro Apex One (Added: 2025-08-18) — Details
- CVE-2025-8876 — N-able N-Central Command Injection Vulnerability — N-able N-Central (Added: 2025-08-13) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2005-10004 — Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authenticated user can inject arbitrary shell commands via the gra… HIGH 8.7 — Details
- CVE-2008-20001 — activePDF WebGrabber version 3.8.2.0 contains a stack-based buffer overflow vulnerability in the GetStatus() method of the APWebGrb.ocx ActiveX control. By passing an overly long s… HIGH 7.5 — Details
- CVE-2009-20008 — Green Dam Youth Escort version 3.17 is vulnerable to a stack-based buffer overflow when processing overly long URLs. The flaw resides in the URL filtering component, which fails to… HIGH 8.6 — Details
- CVE-2009-20009 — Belkin Bulldog Plus version 4.0.2 build 1219 contains a stack-based buffer overflow vulnerability in its web service authentication handler. When a specially crafted HTTP request i… CRITICAL 9.3 — Details
- CVE-2009-20010 — Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail subsystem. The vulnerability arises from unsanitized user inpu… CRITICAL 9.3 — Details
- CVE-2009-20011 — ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the… CRITICAL 10.0 — Details
📰 Security News
Top headlines from trusted sources.
- OpenAI is testing "Thinking effort" for ChatGPT
— Sun, 31 Aug 2025 11:26:42 GMT - TamperedChef infostealer delivered through fraudulent PDF Editor
— Sat, 30 Aug 2025 16:22:51 GMT - Windows 11 KB5064081 update clears up CPU usage metrics in Task Manager
— Fri, 29 Aug 2025 18:57:04 GMT - Microsoft fixes bug behind Windows certificate enrollment errors
— Fri, 29 Aug 2025 18:02:25 GMT - WhatsApp patches vulnerability exploited in zero-day attacks
— Fri, 29 Aug 2025 16:31:23 GMT - Microsoft to enforce MFA for Azure resource management in October
— Fri, 29 Aug 2025 15:56:47 GMT
Comments
Post a Comment