Cyber Threat Digest – 2025-10-08

🔥 Known Exploited Vulnerabilities (CISA KEV)

1 exploited vulns of note in the last 48 hours.

  • CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details

⚠️ Recent CVEs (NVD)

Latest CVEs with CVSS badges.

  • CVE-2021-22291 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V… HIGH 8.5Details
  • CVE-2025-11397 — A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. Performing manipula… MEDIUM 6.9Details
  • CVE-2025-25009 — Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. HIGH 8.7Details
  • CVE-2025-37728 — Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrik… MEDIUM 5.4Details
  • CVE-2025-48826 — A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to memory corruption. A… HIGH 8.8Details
  • CVE-2025-50505 — Clash Verge Rev thru 2.2.3 forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, al… — Details

📰 Security News

Top headlines from trusted sources.

Comments

Popular posts from this blog

Cyber Threat Digest – 2025-09-14

Cyber Threat Digest – 2025-09-06

Cyber Threat Digest – 2025-10-16