Cyber Threat Digest – 2025-10-04
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2014-6278 — GNU Bash OS Command Injection Vulnerability — GNU GNU Bash (Added: 2025-10-02) — Details
- CVE-2017-1000353 — Jenkins Remote Code Execution Vulnerability — Jenkins Jenkins (Added: 2025-10-02) — Details
- CVE-2015-7755 — Juniper ScreenOS Improper Authentication Vulnerability — Juniper ScreenOS (Added: 2025-10-02) — Details
- CVE-2025-21043 — Samsung Mobile Devices Out-of-Bounds Write Vulnerability — Samsung Mobile Devices (Added: 2025-10-02) — Details
- CVE-2025-4008 — Smartbedded Meteobridge Command Injection Vulnerability — Smartbedded Meteobridge (Added: 2025-10-02) — Details
- CVE-2025-32463 — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability — Sudo Sudo (Added: 2025-09-29) — Details
- CVE-2025-59689 — Libraesva Email Security Gateway Command Injection Vulnerability — Libraesva Email Security Gateway (Added: 2025-09-29) — Details
- CVE-2025-10035 — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability — Fortra GoAnywhere MFT (Added: 2025-09-29) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-59489 — Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an applic… HIGH 7.4 — Details
- CVE-2025-60445 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in XunRuiCMS version 4.7.1. The vulnerability exists due to insufficient validation of SVG file uploads in the… MEDIUM 6.1 — Details
- CVE-2025-60447 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists in the email template configuration component located at /admin/… MEDIUM 5.9 — Details
- CVE-2025-60448 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin… MEDIUM 6.1 — Details
- CVE-2025-60449 — An information disclosure vulnerability has been discovered in SeaCMS 13.1. The vulnerability exists in the admin_safe.php component located in the /btcoan/ directory. This securit… MEDIUM 4.9 — Details
- CVE-2025-60450 — A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists due to insufficient validation and sanitization of SVG fi… MEDIUM 6.1 — Details
📰 Security News
Top headlines from trusted sources.
- Hackers steal identifiable Discord user data in third-party breach
— Sat, 04 Oct 2025 11:16:33 GMT - Opera wants you to pay $19.90 per month for its new AI browser
— Fri, 03 Oct 2025 23:54:49 GMT - Signal adds new cryptographic defense against quantum attacks
— Fri, 03 Oct 2025 17:15:44 GMT - Renault and Dacia UK warn of data breach impacting customers
— Fri, 03 Oct 2025 15:52:08 GMT - Japanese beer giant Asahi confirms ransomware attack
— Fri, 03 Oct 2025 14:51:00 GMT - ShinyHunters launches Salesforce data leak site to extort 39 victims
— Fri, 03 Oct 2025 14:16:16 GMT
Comments
Post a Comment