Cyber Threat Digest – 2025-10-02
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-32463 — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Sudo Sudo (Added: 2025-09-29) — Details
- CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability — Libraesva Email Security Gateway (Added: 2025-09-29) — Details
- CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability — Fortra GoAnywhere MFT (Added: 2025-09-29) — Details
- CVE-2025-20352 — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability — Cisco IOS and IOS XE (Added: 2025-09-29) — Details
- CVE-2021-21311 — Adminer Server-Side Request Forgery Vulnerability — Adminer Adminer (Added: 2025-09-29) — Details
- CVE-2025-20362 — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense (Added: 2025-09-25) — Details
- CVE-2025-20333 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense (Added: 2025-09-25) — Details
- CVE-2025-10585 — Google Chromium V8 Type Confusion Vulnerability — Google Chromium V8 (Added: 2025-09-23) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-41421 — Improper handling of symbolic links in the TeamViewer Full Client and Host for Windows — in versions prior to 15.70 of TeamViewer Remote and Tensor — allows an attacker with local,… MEDIUM 4.7 — Details
- CVE-2025-52039 — In Frappe ERPNext 15.57.5, the function get_material_requests_based_on_supplier() at erpnext/stock/doctype/material_request/material_request.py is vulnerable to SQL Injection, whic… HIGH 8.2 — Details
- CVE-2025-52040 — In Frappe ERPNext 15.57.5, the function get_blanket_orders() at erpnext/controllers/queries.py is vulnerable to SQL Injection, which allows an attacker can extract all information … HIGH 8.2 — Details
- CVE-2025-52041 — In Frappe ERPNext 15.57.5, the function get_stock_balance_for() at erpnext/stock/doctype/stock_reconciliation/stock_reconciliation.py is vulnerable to SQL Injection, which allows a… HIGH 8.2 — Details
- CVE-2025-52042 — In Frappe ERPNext 15.57.5, the function get_rfq_containing_supplier() at erpnext/buying/doctype/request_for_quotation/request_for_quotation.py is vulnerable to SQL Injection, which… HIGH 8.2 — Details
- CVE-2025-57275 — Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf. — Details
📰 Security News
Top headlines from trusted sources.
- Android spyware campaigns impersonate Signal and ToTok messengers
— Thu, 02 Oct 2025 10:53:18 GMT - Red Hat confirms security incident after hackers claim GitHub breach
— Thu, 02 Oct 2025 06:15:17 GMT - Clop extortion emails claim theft of Oracle E-Business Suite data
— Thu, 02 Oct 2025 03:13:58 GMT - Data breach at dealership software provider impacts 766k clients
— Wed, 01 Oct 2025 20:37:08 GMT - Adobe Analytics bug leaked customer tracking data to other tenants
— Wed, 01 Oct 2025 19:58:04 GMT - New bug in classic Outlook can only be fixed via Microsoft support
— Wed, 01 Oct 2025 18:43:41 GMT
Comments
Post a Comment