Cyber Threat Digest – 2025-10-28
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
- CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager (Added: 2025-10-22) — Details
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
- CVE-2025-2746 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-2747 — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability — Kentico Xperience CMS (Added: 2025-10-20) — Details
- CVE-2025-33073 — Microsoft Windows SMB Client Improper Access Control Vulnerability — Microsoft Windows (Added: 2025-10-20) — Details
- CVE-2025-61884 — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability — Oracle E-Business Suite (Added: 2025-10-20) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-12280 — A vulnerability was found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /update-clients.php. Performing manipulation results in… MEDIUM 4.8 — Details
- CVE-2025-12281 — A vulnerability was determined in code-projects Client Details System 1.0. Impacted is an unknown function of the file /admin/clientview.php. Executing manipulation can lead to cro… MEDIUM 4.8 — Details
- CVE-2025-12282 — A vulnerability was identified in code-projects Client Details System 1.0. The affected element is an unknown function of the file /admin/manage-users.php. The manipulation leads t… MEDIUM 4.8 — Details
- CVE-2025-12283 — A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown function. The manipulation results in authorization bypass. The a… MEDIUM 5.3 — Details
- CVE-2025-12286 — A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)\VeePN\avservice\avservice.exe of the component AVService. T… HIGH 7.3 — Details
- CVE-2025-50055 — Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer S… — Details
📰 Security News
Top headlines from trusted sources.
- New Atroposia malware comes with a local vulnerability scanner
— Tue, 28 Oct 2025 13:15:11 GMT - New Herodotus Android malware fakes human typing to avoid detection
— Tue, 28 Oct 2025 10:00:00 GMT - Google disputes false claims of massive Gmail data breach
— Mon, 27 Oct 2025 20:32:01 GMT - X: Re-enroll 2FA security keys by November 10 or get locked out
— Mon, 27 Oct 2025 19:36:11 GMT - Ransomware profits drop as victims stop paying hackers
— Mon, 27 Oct 2025 19:22:38 GMT - Windows will soon prompt for memory scans after BSOD crashes
— Mon, 27 Oct 2025 18:36:05 GMT
Comments
Post a Comment