Cyber Threat Digest – 2025-10-03
🔥 Known Exploited Vulnerabilities (CISA KEV)
5 exploited vulns of note in the last 48 hours.
- CVE-2014-6278 — GNU Bash OS Command Injection Vulnerability — GNU GNU Bash (Added: 2025-10-02) — Details
- CVE-2017-1000353 — Jenkins Remote Code Execution Vulnerability — Jenkins Jenkins (Added: 2025-10-02) — Details
- CVE-2015-7755 — Juniper ScreenOS Improper Authentication Vulnerability — Juniper ScreenOS (Added: 2025-10-02) — Details
- CVE-2025-21043 — Samsung Mobile Devices Out-of-Bounds Write Vulnerability — Samsung Mobile Devices (Added: 2025-10-02) — Details
- CVE-2025-4008 — Smartbedded Meteobridge Command Injection Vulnerability — Smartbedded Meteobridge (Added: 2025-10-02) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2023-28760 — TP-Link AX1800 WiFi 6 Router (Archer AX21) devices allow unauthenticated attackers (on the LAN) to execute arbitrary code as root via the db_dir field to minidlnad. The attacker ob… HIGH 7.5 — Details
- CVE-2025-53881 — A UNIX Symbolic Link (Symlink) Following vulnerability in logrotate config in the exim package allowed privilege escalation from mail user/group to root.This issue affects Tumblewe… MEDIUM 6.9 — Details
- CVE-2025-56379 — A stored cross-site scripting (XSS) vulnerability in the blog post feature of ERPNEXT v15.67.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec… — Details
- CVE-2025-56380 — Frappe Framework v15.72.4 was discovered to contain a SQL injection vulnerability via the fieldname parameter in the frappe.client.get_value API endpoint and a crafted script to th… MEDIUM 6.5 — Details
- CVE-2025-56381 — ERPNEXT v15.67.0 was discovered to contain multiple SQL injection vulnerabilities in the /api/method/frappe.desk.reportview.get endpoint via the order_by and group_by parameters. MEDIUM 6.5 — Details
- CVE-2025-59735 — Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a PO… CRITICAL 9.3 — Details
📰 Security News
Top headlines from trusted sources.
- Oracle links Clop extortion attacks to July 2025 vulnerabilities
— Fri, 03 Oct 2025 12:14:29 GMT - Gmail business users can now send encrypted emails to anyone
— Fri, 03 Oct 2025 11:18:11 GMT - Microsoft Outlook stops displaying inline SVG images used in attacks
— Thu, 02 Oct 2025 18:13:37 GMT - DrayTek warns of remote code execution bug in Vigor routers
— Thu, 02 Oct 2025 17:37:46 GMT - HackerOne paid $81 million in bug bounties over the past year
— Thu, 02 Oct 2025 15:35:44 GMT - Brave browser surpasses the 100 million active monthly users mark
— Thu, 02 Oct 2025 15:07:56 GMT
Comments
Post a Comment