Cyber Threat Digest – 2025-10-22
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
- CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-2747 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-20) — Details
- CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability — Oracle E-Business Suite (Added: 2025-10-20) — Details
- CVE-2025-54253 — Adobe Experience Manager Forms Code Execution Vulnerability — Adobe Experience Manager (AEM) Forms (Added: 2025-10-15) — Details
- CVE-2025-47827 — IGEL OS Use of a Key Past its Expiration Date Vulnerability — IGEL IGEL OS (Added: 2025-10-14) — Details
- CVE-2025-24990 — Microsoft Windows Untrusted Pointer Dereference Vulnerability — Microsoft Windows (Added: 2025-10-14) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-11151 — Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beyaz Bilgisayar Software De… HIGH 8.2 — Details
- CVE-2025-11624 — Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller… LOW 1.8 — Details
- CVE-2025-11625 — Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials. CRITICAL 9.4 — Details
- CVE-2025-9339 — SQL injection vulnerability in the fields of warehouse document filtering form in SIMPLE.ERP software allows logged-in user to send a payload of up to 20 characters. Identified use… HIGH 7.1 — Details
- CVE-2020-36855 — A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument Storage… MEDIUM 4.8 — Details
- CVE-2022-4981 — A vulnerability was detected in DCMTK up to 3.6.7. The impacted element is the function DcmQueryRetrieveConfig::readPeerList of the file /dcmqrcnf.cc of the component dcmqrscp. The… MEDIUM 4.8 — Details
📰 Security News
Top headlines from trusted sources.
- PhantomCaptcha ClickFix attack targets Ukraine war relief orgs
— Wed, 22 Oct 2025 13:37:17 GMT - Sharepoint ToolShell attacks targeted orgs across four continents
— Wed, 22 Oct 2025 10:24:29 GMT - Vidar Stealer 2.0 adds multi-threaded data theft, better evasion
— Tue, 21 Oct 2025 22:26:02 GMT - TP-Link warns of critical command injection flaw in Omada gateways
— Tue, 21 Oct 2025 21:11:35 GMT - CISA confirms hackers exploited Oracle E-Business Suite SSRF flaw
— Tue, 21 Oct 2025 19:15:34 GMT - Cursor, Windsurf IDEs riddled with 94+ n-day Chromium vulnerabilities
— Tue, 21 Oct 2025 19:00:00 GMT
Comments
Post a Comment