Cyber Threat Digest – 2025-11-03
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability — Broadcom VMware Aria Operations and VMware Tools (Added: 2025-10-30) — Details
- CVE-2025-24893 — XWiki Platform Eval Injection Vulnerability — XWiki Platform (Added: 2025-10-30) — Details
- CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-6205 — Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
- CVE-2025-61932 — Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability — Motex LANSCOPE Endpoint Manager (Added: 2025-10-22) — Details
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability — Apple Multiple Products (Added: 2025-10-20) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-12604 — A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_i… MEDIUM 6.9 — Details
- CVE-2025-12605 — A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument … MEDIUM 6.9 — Details
- CVE-2025-12606 — A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of … MEDIUM 6.9 — Details
- CVE-2025-12607 — A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument… MEDIUM 6.9 — Details
- CVE-2025-12608 — A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipula… MEDIUM 6.9 — Details
- CVE-2025-12609 — A vulnerability was found in CodeAstro Gym Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/update-progress.php. Performing manipulati… MEDIUM 5.1 — Details
📰 Security News
Top headlines from trusted sources.
- Microsoft: Windows Task Manager won't quit after KB5067036 update
— Mon, 03 Nov 2025 10:12:47 GMT - Penn hacker claims to have stolen 1.2 million donor records in data breach
— Sun, 02 Nov 2025 22:07:14 GMT - Open VSX rotates access tokens used in supply-chain malware attack
— Sun, 02 Nov 2025 15:09:19 GMT - OpenAI is going Meta route, as it considers memory-based ads on ChatGPT
— Sat, 01 Nov 2025 20:00:00 GMT - Google confirms AI search will have ads, but they may look different
— Sat, 01 Nov 2025 16:56:00 GMT - Windows 11 Build 26220.7051 released with "Ask Copilot" feature
— Sat, 01 Nov 2025 16:17:22 GMT
Comments
Post a Comment