Cyber Threat Digest – 2025-10-13
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
- CVE-2021-22555 — Linux Kernel Heap Out-of-Bounds Write Vulnerability — Linux Kernel (Added: 2025-10-06) — Details
- CVE-2010-3962 — Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability — Microsoft Internet Explorer (Added: 2025-10-06) — Details
- CVE-2021-43226 — Microsoft Windows Privilege Escalation Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2013-3918 — Microsoft Windows Out-of-Bounds Write Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2011-3402 — Microsoft Windows Remote Code Execution Vulnerability — Microsoft Windows (Added: 2025-10-06) — Details
- CVE-2010-3765 — Mozilla Multiple Products Remote Code Execution Vulnerability — Mozilla Multiple Products (Added: 2025-10-06) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11635 — A weakness has been identified in Tomofun Furbo 360 up to FB0035_FW_036. This vulnerability affects unknown code of the component File Upload. This manipulation causes resource con… MEDIUM 5.3 — Details
- CVE-2025-2138 — IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete comments from other users due to client-side e… LOW 3.5 — Details
- CVE-2025-2139 — IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to delete reviews from other users due to client-side enfo… LOW 3.5 — Details
- CVE-2025-2140 — IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user on the network to spoof email identity of the sender due to improper veri… MEDIUM 5.7 — Details
- CVE-2025-33096 — IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an authenticated user to cause a denial of service by uploading specially crafted files using u… MEDIUM 6.5 — Details
- CVE-2025-11636 — A security vulnerability has been detected in Tomofun Furbo 360 up to FB0035_FW_036. This issue affects some unknown processing of the component Account Handler. Such manipulation … MEDIUM 6.3 — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft: Windows 11 Media Creation Tool broken on Windows 10 PCs
— Mon, 13 Oct 2025 13:22:16 GMT - Harvard investigating breach linked to Oracle zero-day exploit
— Mon, 13 Oct 2025 11:14:21 GMT - Fake 'Inflation Refund' texts target New Yorkers in new scam
— Sun, 12 Oct 2025 14:19:29 GMT - Spain dismantles "GXC Team" cybercrime syndicate, arrests leader
— Sat, 11 Oct 2025 14:17:42 GMT - Windows 11 23H2 Home and Pro reach end of support in 30 days
— Fri, 10 Oct 2025 19:34:13 GMT - Hackers exploiting zero-day in Gladinet file sharing software
— Fri, 10 Oct 2025 19:08:12 GMT
Comments
Post a Comment