Cyber Threat Digest – 2025-11-01
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability — Broadcom VMware Aria Operations and VMware Tools (Added: 2025-10-30) — Details
- CVE-2025-24893 — XWiki Platform Eval Injection Vulnerability — XWiki Platform (Added: 2025-10-30) — Details
- CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-6205 — Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
- CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager (Added: 2025-10-22) — Details
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-12460 — An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially crafted HTML e-mail message with JavaScript in an img HTML tag. T… MEDIUM 5.3 — Details
- CVE-2025-12521 — The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.0.3 via the Analytify Tag HTML details. This makes it… MEDIUM 5.3 — Details
- CVE-2025-64386 — The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the… HIGH 7.7 — Details
- CVE-2025-12501 — Integer overflow in GameMaker IDE below 2024.14.0 version can lead to can lead to application crashes through denial-of-service attacks (DoS). GameMaker users who use the network_c… HIGH 7.5 — Details
- CVE-2025-57106 — Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template funct… HIGH 7.5 — Details
- CVE-2025-57107 — Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy con… HIGH 7.1 — Details
📰 Security News
Top headlines from trusted sources.
- Windows 11 tests shared Bluetooth audio support, but only for AI PCs
— Fri, 31 Oct 2025 20:59:02 GMT - 'We got hacked' emails threaten to leak University of Pennsylvania data
— Fri, 31 Oct 2025 18:32:39 GMT - Microsoft Edge gets scareware sensor for faster scam detection
— Fri, 31 Oct 2025 17:15:06 GMT - Australia warns of BadCandy infections on unpatched Cisco devices
— Fri, 31 Oct 2025 15:38:55 GMT - Why password controls still matter in cybersecurity
— Fri, 31 Oct 2025 14:02:12 GMT - Alleged Meduza Stealer malware admins arrested after hacking Russian org
— Fri, 31 Oct 2025 13:45:17 GMT
Comments
Post a Comment