Cyber Threat Digest – 2025-10-12
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
- CVE-2021-22555 — Linux Kernel Heap Out-of-Bounds Write Vulnerability — Linux Kernel (Added: 2025-10-06) — Details
- CVE-2010-3962 — Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability — Microsoft Internet Explorer (Added: 2025-10-06) — Details
- CVE-2021-43226 — Microsoft Windows Privilege Escalation Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2010-3765 — Mozilla Multiple Products Remote Code Execution Vulnerability — Mozilla Multiple Products (Added: 2025-10-06) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11603 — A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of the file /editproduct.php. The manipulation of the argument C… MEDIUM 5.3 — Details
- CVE-2025-11604 — A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown processing of the file /all-orders.php. This manipulation of the ar… MEDIUM 6.9 — Details
- CVE-2025-11605 — A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/update-profile.php. Such manipulation of the argument … MEDIUM 5.3 — Details
- CVE-2025-11606 — A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The affected element is an unknown function of the component Se… MEDIUM 5.3 — Details
- CVE-2025-11607 — A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_music of the file app/controllers/v1/music.py of the componen… MEDIUM 5.3 — Details
- CVE-2025-11608 — A security vulnerability has been detected in code-projects E-Banking System 1.0. This affects an unknown function of the file /register.php of the component POST Parameter Handler… MEDIUM 6.9 — Details
📰 Security News
Top headlines from trusted sources.
- Windows 11 23H2 Home and Pro reach end of support in 30 days
— Fri, 10 Oct 2025 19:34:13 GMT - Hackers exploiting zero-day in Gladinet file sharing software
— Fri, 10 Oct 2025 19:08:12 GMT - Cybersecurity For Dummies, 3rd Edition eBook FREE for a Limited Time
— Fri, 10 Oct 2025 18:11:25 GMT - Google Chrome to revoke notification access for inactive sites
— Fri, 10 Oct 2025 17:00:00 GMT - Apple now offers $2 million for zero-click RCE vulnerabilities
— Fri, 10 Oct 2025 16:50:35 GMT - Copilot on Windows can now connect to email, create Office docs
— Fri, 10 Oct 2025 14:49:09 GMT
Comments
Post a Comment