Cyber Threat Digest – 2025-11-05
🔥 Known Exploited Vulnerabilities (CISA KEV)
2 exploited vulns of note in the last 48 hours.
- CVE-2025-48703 — CWP Control Web Panel OS Command Injection Vulnerability — CWP Control Web Panel (Added: 2025-11-04) — Details
- CVE-2025-11371 — Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability — Gladinet CentreStack and Triofox (Added: 2025-11-04) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-12184 — The MeetingList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 0.11 due to insufficient input sanitizati… MEDIUM 4.4 — Details
- CVE-2025-63294 — WorkDo HRM SaaS HR and Payroll Tool 8.1 is affected vulnerable to Insecure Permissions. An authenticated user can create leave or resignation records on behalf of other users. MEDIUM 6.5 — Details
- CVE-2025-54323 — An issue was discovered in the camera in Samsung Mobile Processor Exynos 980, 990, 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, and 1580. Improper debug printing leads to i… HIGH 7.5 — Details
- CVE-2025-54329 — An issue was discovered in NAS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1… HIGH 7.5 — Details
- CVE-2025-54330 — An issue was discovered in NPU in Samsung Mobile Processor Exynos through July 2025. There is an Out-of-bounds Read of q->bufs[] in the __is_done_for_me function. MEDIUM 5.3 — Details
- CVE-2025-54331 — An issue was discovered in NPU in Samsung Mobile Processor Exynos through July 2025. There is an Untrusted Pointer Dereference of src_hdr in the copy_ncp_header function. MEDIUM 5.3 — Details
📰 Security News
Top headlines from trusted sources.
- Google warns of new AI-powered malware families deployed in the wild
— Wed, 05 Nov 2025 14:59:59 GMT - Police busts credit card fraud rings with 4.3 million victims
— Wed, 05 Nov 2025 12:29:24 GMT - US sanctions North Korean bankers linked to cybercrime, IT worker fraud
— Wed, 05 Nov 2025 10:34:38 GMT - Microsoft: October Windows updates trigger BitLocker recovery
— Wed, 05 Nov 2025 08:56:22 GMT - Hackers exploit WordPress plugin Post SMTP to hijack admin accounts
— Tue, 04 Nov 2025 21:46:50 GMT - Apache OpenOffice disputes data breach claims by ransomware gang
— Tue, 04 Nov 2025 21:18:43 GMT
Comments
Post a Comment