Cyber Threat Digest – 2025-09-30

🔥 Known Exploited Vulnerabilities (CISA KEV)

5 exploited vulns of note in the last 48 hours.

  • CVE-2025-32463 — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Sudo Sudo (Added: 2025-09-29) — Details
  • CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability — Libraesva Email Security Gateway (Added: 2025-09-29) — Details
  • CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability — Fortra GoAnywhere MFT (Added: 2025-09-29) — Details
  • CVE-2025-20352 — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability — Cisco IOS and IOS XE (Added: 2025-09-29) — Details
  • CVE-2021-21311 — Adminer Server-Side Request Forgery Vulnerability — Adminer Adminer (Added: 2025-09-29) — Details

⚠️ Recent CVEs (NVD)

Latest CVEs with CVSS badges.

  • CVE-2025-57428 — Default credentials in Italy Wireless Mini Router WIRELESS-N 300M v28K.MiniRouter.20190211 allows attackers to gain access to the debug shell exposed via Telnet on Port 23 and exec… — Details
  • CVE-2025-36351 — IBM License Metric Tool 9.2.0 through 9.2.40 could allow an authenticated user to bypass access controls in the REST API interface and perform unauthorized actions. MEDIUM 4.3Details
  • CVE-2025-36352 — IBM License Metric Tool 9.2.0 through 9.2.40 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the… MEDIUM 6.4Details
  • CVE-2025-55795 — The openml/openml.org web application version v2.0.20241110 uses incremental user IDs and insufficient email ownership verification during email update workflows. An authenticated … LOW 3.5Details
  • CVE-2025-56449 — A security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling in MFA (e.g. after the 7-day enforcement… — Details
  • CVE-2025-57516 — OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or… — Details

📰 Security News

Top headlines from trusted sources.

Comments

Popular posts from this blog

Cyber Threat Digest – 2025-09-14

Cyber Threat Digest – 2025-09-06

Cyber Threat Digest – 2025-09-05