Cyber Threat Digest – 2025-10-18
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager (AEM) Forms (Added: 2025-10-15) — Details
- CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
- CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-6264 — Rapid7 Velociraptor Incorrect Default Permissions Vulnerability — Rapid7 Velociraptor (Added: 2025-10-14) — Details
- CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability — SKYSEA Client View (Added: 2025-10-14) — Details
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11902 — A vulnerability was detected in yanyutao0402 ChanCMS up to 3.3.2. Affected by this vulnerability is the function findField of the file /cms/article/findField. Performing manipulati… MEDIUM 5.3 — Details
- CVE-2025-11903 — A flaw has been found in yanyutao0402 ChanCMS up to 3.3.2. Affected by this issue is the function update of the file /cms/article/update. Executing manipulation of the argument cid… MEDIUM 5.3 — Details
- CVE-2025-48044 — Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated with program files lib/ash/policy/policy.ex and program rout… HIGH 8.6 — Details
- CVE-2025-60359 — radare2 v5.9.8 and before contains a memory leak in the function r_bin_object_new. MEDIUM 4.0 — Details
- CVE-2025-60360 — radare2 v5.9.8 and before contains a memory leak in the function r2r_subprocess_init. LOW 3.3 — Details
- CVE-2025-11904 — A vulnerability has been found in yanyutao0402 ChanCMS up to 3.3.2. This affects the function hasUse of the file /cms/model/hasUse. The manipulation of the argument ID leads to sql… MEDIUM 5.3 — Details
📰 Security News
Top headlines from trusted sources.
- ConnectWise fixes Automate bug allowing AiTM update attacks
— Fri, 17 Oct 2025 19:29:22 GMT - American Airlines subsidiary Envoy confirms Oracle data theft attack
— Fri, 17 Oct 2025 19:11:52 GMT - Microsoft lifts more safeguard holds blocking Windows 11 updates
— Fri, 17 Oct 2025 17:22:16 GMT - Europol dismantles SIM box operation renting numbers for cybercrime
— Fri, 17 Oct 2025 17:01:51 GMT - Microsoft fixes highest-severity ASP.NET Core flaw ever
— Fri, 17 Oct 2025 15:35:49 GMT - VMware Certification: Your Next Career Power Move
— Fri, 17 Oct 2025 14:02:12 GMT
Comments
Post a Comment