Cyber Threat Digest – 2025-10-04

🔥 Known Exploited Vulnerabilities (CISA KEV)

8 exploited vulns of note.

  • CVE-2014-6278 — GNU Bash OS Command Injection Vulnerability — GNU GNU Bash (Added: 2025-10-02) — Details
  • CVE-2017-1000353 — Jenkins Remote Code Execution Vulnerability — Jenkins Jenkins (Added: 2025-10-02) — Details
  • CVE-2015-7755 — Juniper ScreenOS Improper Authentication Vulnerability — Juniper ScreenOS (Added: 2025-10-02) — Details
  • CVE-2025-21043 — Samsung Mobile Devices Out-of-Bounds Write Vulnerability — Samsung Mobile Devices (Added: 2025-10-02) — Details
  • CVE-2025-4008 — Smartbedded Meteobridge Command Injection Vulnerability — Smartbedded Meteobridge (Added: 2025-10-02) — Details
  • CVE-2025-32463 — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Sudo Sudo (Added: 2025-09-29) — Details
  • CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability — Libraesva Email Security Gateway (Added: 2025-09-29) — Details
  • CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability — Fortra GoAnywhere MFT (Added: 2025-09-29) — Details

⚠️ Recent CVEs (NVD)

Latest CVEs with CVSS badges.

  • CVE-2025-59489 — Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an applic… HIGH 7.4Details
  • CVE-2025-60445 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in the… MEDIUM 6.1Details
  • CVE-2025-60447 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/… MEDIUM 5.9Details
  • CVE-2025-60448 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin… MEDIUM 6.1Details
  • CVE-2025-60449 — An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This securit… MEDIUM 4.9Details
  • CVE-2025-60450 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG fi… MEDIUM 6.1Details

📰 Security News

Top headlines from trusted sources.

Comments

Popular posts from this blog

Cyber Threat Digest – 2025-09-14

Cyber Threat Digest – 2025-09-06

Cyber Threat Digest – 2025-09-05