Cyber Threat Digest – 2025-09-03
π₯ Known Exploited Vulnerabilities (CISA KEV)
2 exploited vulns of note in the last 48 hours.
- CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability — TP-Link TL-WA855RE (Added: 2025-09-02) — Details
- CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability — Meta Platforms WhatsApp (Added: 2025-09-02) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2024-12974 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft ProKuafΓΆr allows Cross-Site Scripting (XSS).This issue affects… MEDIUM 4.3 — Details
- CVE-2025-0670 — Authorization Bypass Through User-Controlled Key vulnerability in Akinsoft ProKuafor allows Resource Leak Exposure.This issue affects ProKuafor: from s1.02.07 before v1.02.08. MEDIUM 4.7 — Details
- CVE-2025-2413 — Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft ProKuafor allows Authentication Bypass.This issue affects ProKuafor: from s1.02.08 before v1.02.… HIGH 8.6 — Details
- CVE-2025-46047 — A User enumeration vulnerability in the /CredentialsServlet/ForgotPassword endpoint in Silverpeas 6.4.1 and 6.4.2 allows remote attackers to determine valid usernames via the Login… MEDIUM 6.5 — Details
- CVE-2025-9784 — A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" … HIGH 7.5 — Details
- CVE-2024-48705 — Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnera… MEDIUM 6.5 — Details
π° Security News
Top headlines from trusted sources.
- Hackers breach fintech firm in attempted $130M bank heist
— Tue, 02 Sep 2025 22:33:50 GMT - Cloudflare hit by data breach in Salesloft Drift supply chain attack
— Tue, 02 Sep 2025 19:54:00 GMT - Cloudflare blocks largest recorded DDoS attack peaking at 11.5 Tbps
— Tue, 02 Sep 2025 15:52:30 GMT - No, Google did not warn 2.5 billion Gmail users to reset passwords
— Tue, 02 Sep 2025 14:57:28 GMT - Jaguar Land Rover says cyberattack 'severely disrupted' production
— Tue, 02 Sep 2025 14:23:11 GMT - Pennsylvania AG Office says ransomware attack behind recent outage
— Tue, 02 Sep 2025 13:20:01 GMT
Comments
Post a Comment