Cyber Threat Digest – 2025-09-13
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-5086 — Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-09-11) — Details
- CVE-2025-38352 — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability — Linux Kernel (Added: 2025-09-04) — Details
- CVE-2025-48543 — Android Runtime Use-After-Free Vulnerability — Android Runtime (Added: 2025-09-04) — Details
- CVE-2025-53690 — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability — Sitecore Multiple Products (Added: 2025-09-04) — Details
- CVE-2023-50224 — TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability — TP-Link TL-WR841N (Added: 2025-09-03) — Details
- CVE-2025-9377 — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability — TP-Link Multiple Routers (Added: 2025-09-03) — Details
- CVE-2020-24363 — TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability — TP-Link TL-WA855RE (Added: 2025-09-02) — Details
- CVE-2025-55177 — Meta Platforms WhatsApp Incorrect Authorization Vulnerability — Meta Platforms WhatsApp (Added: 2025-09-02) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-10364 — The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management inte… CRITICAL 9.3 — Details
- CVE-2025-10365 — The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a web management interface on port 80. This web management inte… CRITICAL 9.3 — Details
- CVE-2025-59058 — httpsig-rs is a Rust implementation of IETF RFC 9421 http message signatures. Prior to version 0.0.19, the HMAC signature comparison is not timing-safe. This makes anyone who uses … MEDIUM 5.9 — Details
- CVE-2025-59139 — Hono is a Web application framework that provides support for any JavaScript runtime. In versions prior to 4.9.7, a flaw in the `bodyLimit` middleware could allow bypassing the con… MEDIUM 5.3 — Details
- CVE-2025-9556 — Langchaingo supports the use of jinja2 syntax when parsing prompts, which is in turn parsed using the gonja library v1.5.3. Gonja supports include and extends syntax to read files… CRITICAL 9.8 — Details
- CVE-2025-10319 — A security flaw has been discovered in JeecgBoot up to 3.8.2. Affected by this issue is some unknown functionality of the file /sys/tenant/exportLog of the component Tenant Log Exp… MEDIUM 5.3 — Details
📰 Security News
Top headlines from trusted sources.
- New HybridPetya ransomware can bypass UEFI Secure Boot
— Fri, 12 Sep 2025 17:18:07 GMT - CISA warns of actively exploited Dassault RCE vulnerability
— Fri, 12 Sep 2025 16:19:39 GMT - Windows 11 23H2 Home and Pro reach end of support in 60 days
— Fri, 12 Sep 2025 16:15:22 GMT - The first three things you'll want during a cyberattack
— Fri, 12 Sep 2025 14:02:12 GMT - Man gets over 4 years in prison for selling unreleased movies
— Fri, 12 Sep 2025 11:36:22 GMT - Samsung patches actively exploited zero-day reported by WhatsApp
— Fri, 12 Sep 2025 09:48:30 GMT
Comments
Post a Comment