Cyber Threat Digest – 2025-10-21
🔥 Known Exploited Vulnerabilities (CISA KEV)
5 exploited vulns of note in the last 48 hours.
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
- CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-2747 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-20) — Details
- CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability — Oracle E-Business Suite (Added: 2025-10-20) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11677 — Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker, in specific configurations where the user provides a callb… MEDIUM 6.3 — Details
- CVE-2025-11678 — Stack-based Buffer Overflow in lws_adns_parse_label in warmcat libwebsockets allows, when the LWS_WITH_SYS_ASYNC_DNS flag is enabled during compilation, to overflow the label_stack… HIGH 7.5 — Details
- CVE-2025-11679 — Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to read… MEDIUM 5.9 — Details
- CVE-2025-11680 — Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write pas… MEDIUM 5.9 — Details
- CVE-2025-61455 — SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The application directly incorporates unsanitized user inputs i… CRITICAL 9.8 — Details
- CVE-2025-41390 — An arbitrary code execution vulnerability exists in the git functionality of Truffle Security Co. TruffleHog 3.90.2. A specially crafted repository can lead to a arbitrary code exe… HIGH 7.8 — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft fixes bug preventing users from opening classic Outlook
— Tue, 21 Oct 2025 12:59:48 GMT - Windows 11 KB5070773 emergency update fixes Windows Recovery issues
— Tue, 21 Oct 2025 09:01:44 GMT - DNS0.EU private DNS service shuts down over sustainability issues
— Mon, 20 Oct 2025 21:05:17 GMT - Microsoft: October updates break USB input in Windows Recovery
— Mon, 20 Oct 2025 19:06:40 GMT - Retail giant Muji halts online sales after ransomware attack on supplier
— Mon, 20 Oct 2025 18:45:33 GMT - Over 75,000 WatchGuard security devices vulnerable to critical RCE
— Mon, 20 Oct 2025 17:42:08 GMT
Comments
Post a Comment