Cyber Threat Digest – 2025-10-01
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-32463 — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Sudo Sudo (Added: 2025-09-29) — Details
- CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability — Libraesva Email Security Gateway (Added: 2025-09-29) — Details
- CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability — Fortra GoAnywhere MFT (Added: 2025-09-29) — Details
- CVE-2025-20352 — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability — Cisco IOS and IOS XE (Added: 2025-09-29) — Details
- CVE-2021-21311 — Adminer Server-Side Request Forgery Vulnerability — Adminer Adminer (Added: 2025-09-29) — Details
- CVE-2025-20362 — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense (Added: 2025-09-25) — Details
- CVE-2025-20333 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense (Added: 2025-09-25) — Details
- CVE-2025-10585 — Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 (Added: 2025-09-23) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-34217 — Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumented 'printerlogic' user with a hardcoded SSH public key in '~/… CRITICAL 10.0 — Details
- CVE-2025-52043 — In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_accounts_importer.py is vulnerable to SQL injection, which all… MEDIUM 6.5 — Details
- CVE-2025-52047 — In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker to extract all information … MEDIUM 6.5 — Details
- CVE-2025-52049 — In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py is vulnerable to SQL Injection, which allows an attacker to … MEDIUM 6.5 — Details
- CVE-2025-52050 — In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_program/loyalty_program.py is vulnerable to SQL Injection, whi… MEDIUM 6.5 — Details
- CVE-2025-9230 — Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bou… HIGH 7.5 — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft: Media Creation Tool broken on Windows 11 Arm64 PCs
— Wed, 01 Oct 2025 14:00:00 GMT - Imgur blocks UK users after data watchdog signals possible fine
— Tue, 30 Sep 2025 21:24:08 GMT - Sendit sued by the FTC for illegal collection of children data
— Tue, 30 Sep 2025 19:57:34 GMT - New MatrixPDF toolkit turns PDFs into phishing and malware lures
— Tue, 30 Sep 2025 18:57:53 GMT - WestJet confirms recent breach exposed customers' passports
— Tue, 30 Sep 2025 18:40:11 GMT - Windows 11 2025 Update (25H2) is now available, Here's what's new
— Tue, 30 Sep 2025 17:58:43 GMT
Comments
Post a Comment