Cyber Threat Digest – 2025-10-08
🔥 Known Exploited Vulnerabilities (CISA KEV)
1 exploited vulns of note in the last 48 hours.
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2021-22291 — Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V… HIGH 8.5 — Details
- CVE-2025-11397 — A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unknown function of the file /login.php. Performing manipula… MEDIUM 6.9 — Details
- CVE-2025-25009 — Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. HIGH 8.7 — Details
- CVE-2025-37728 — Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A malicious user can access cached credentials from a Crowdstrik… MEDIUM 5.4 — Details
- CVE-2025-48826 — A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to memory corruption. A… HIGH 8.8 — Details
- CVE-2025-50505 — Clash Verge Rev thru 2.2.3 forces the installation of system services(clash-verge-service) by default and exposes key functions through the unauthorized HTTP API `/start_clash`, al… — Details
📰 Security News
Top headlines from trusted sources.
- Salesforce refuses to pay ransom over widespread data theft attacks
— Wed, 08 Oct 2025 00:17:17 GMT - Docker makes Hardened Images Catalog affordable for small businesses
— Tue, 07 Oct 2025 22:09:48 GMT - Google won't fix new ASCII smuggling attack in Gemini
— Tue, 07 Oct 2025 20:35:40 GMT - DraftKings warns of account breaches in credential stuffing attacks
— Tue, 07 Oct 2025 19:09:36 GMT - Clop exploited Oracle zero-day for data theft since early August
— Tue, 07 Oct 2025 17:27:34 GMT - North Korean hackers stole over $2 billion in crypto this year
— Tue, 07 Oct 2025 17:02:35 GMT
Comments
Post a Comment