Cyber Threat Digest – 2025-10-20
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager (AEM) Forms (Added: 2025-10-15) — Details
- CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
- CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-59230 — Microsoft Windows Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
- CVE-2025-6264 — Rapid7 Velociraptor Incorrect Default Permissions Vulnerability — Rapid7 Velociraptor (Added: 2025-10-14) — Details
- CVE-2016-7836 — SKYSEA Client View Improper Authentication Vulnerability — SKYSEA Client View (Added: 2025-10-14) — Details
- CVE-2021-43798 — Grafana Path Traversal Vulnerability — Grafana Labs Grafana (Added: 2025-10-09) — Details
- CVE-2025-27915 — Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability — Synacor Zimbra Collaboration Suite (ZCS) (Added: 2025-10-07) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11941 — A vulnerability was detected in e107 CMS up to 2.3.3. This impacts an unknown function of the file /e107_admin/image.php?mode=main&action=avatar of the component Avatar Handler… MEDIUM 5.3 — Details
- CVE-2025-11942 — A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing manipulation can lead to missing authentication. It is possi… MEDIUM 6.9 — Details
- CVE-2025-11943 — A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality of the component HTTP Web Server. The manipulation leads to … MEDIUM 6.9 — Details
- CVE-2025-11944 — A vulnerability was determined in givanz Vvveb up to 1.0.7.3. This affects the function Import of the file admin/controller/tools/import.php of the component Raw SQL Handler. This … MEDIUM 5.1 — Details
- CVE-2025-11945 — A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the component Avatar Upload Image Endpoint. Such manipulation leads t… MEDIUM 5.1 — Details
- CVE-2025-11946 — A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown processing of the file /frontend.jsp of the component Add Contact P… MEDIUM 5.1 — Details
📰 Security News
Top headlines from trusted sources.
- AWS outage crashes Amazon, Prime Video, Fortnite, Perplexity and more
— Mon, 20 Oct 2025 08:24:25 GMT - TikTok videos continue to push infostealers in ClickFix attacks
— Sun, 19 Oct 2025 18:28:25 GMT - Experian fined $3.2 million for mass-collecting personal data
— Sun, 19 Oct 2025 14:24:36 GMT - OpenAI confirms GPT-6 is not shipping in 2025
— Sat, 18 Oct 2025 21:51:29 GMT - Google ads for fake Homebrew, LogMeIn sites push infostealers
— Sat, 18 Oct 2025 15:02:19 GMT - ConnectWise fixes Automate bug allowing AiTM update attacks
— Fri, 17 Oct 2025 19:29:22 GMT
Comments
Post a Comment