Cyber Threat Digest – 2025-10-18

🔥 Known Exploited Vulnerabilities (CISA KEV)

8 exploited vulns of note.

  • CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager (AEM) Forms (Added: 2025-10-15) — Details
  • CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
  • CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
  • CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
  • CVE-2025-6264 — Rapid7 Velociraptor Incorrect Default Permissions Vulnerability — Rapid7 Velociraptor (Added: 2025-10-14) — Details
  • CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability — SKYSEA Client View (Added: 2025-10-14) — Details
  • CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
  • CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details

⚠️ Recent CVEs (NVD)

Latest CVEs with CVSS badges.

  • CVE-2025-11902 — A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/findField. Performing manipulati… MEDIUM 5.3Details
  • CVE-2025-11903 — A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing manipulation of the argument cid… MEDIUM 5.3Details
  • CVE-2025-48044 — Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program rout… HIGH 8.6Details
  • CVE-2025-60359 — radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new. MEDIUM 4.0Details
  • CVE-2025-60360 — radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init. LOW 3.3Details
  • CVE-2025-11904 — A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument ID leads to sql… MEDIUM 5.3Details

📰 Security News

Top headlines from trusted sources.

Comments

Popular posts from this blog

Cyber Threat Digest – 2025-09-14

Cyber Threat Digest – 2025-09-06

Cyber Threat Digest – 2025-10-16