Cyber Threat Digest – 2025-11-06
🔥 Known Exploited Vulnerabilities (CISA KEV)
8 exploited vulns of note.
- CVE-2025-48703 — CWP Control Web Panel OS Command Injection Vulnerability — CWP Control Web Panel (Added: 2025-11-04) — Details
- CVE-2025-11371 — Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability — Gladinet CentreStack and Triofox (Added: 2025-11-04) — Details
- CVE-2025-41244 — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability — Broadcom VMware Aria Operations and VMware Tools (Added: 2025-10-30) — Details
- CVE-2025-24893 — XWiki Platform Eval Injection Vulnerability — XWiki Platform (Added: 2025-10-30) — Details
- CVE-2025-6204 — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-6205 — Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability — Dassault Systèmes DELMIA Apriso (Added: 2025-10-28) — Details
- CVE-2025-54236 — Adobe Commerce and Magento Improper Input Validation Vulnerability — Adobe Commerce and Magento (Added: 2025-10-24) — Details
- CVE-2025-59287 — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability — Microsoft Windows (Added: 2025-10-24) — Details
⚠️ Recent CVEs (NVD)
Latest CVEs with CVSS badges.
- CVE-2025-3125 — An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAppUploader admin service endpoint. An authenticated attacker … MEDIUM 6.7 — Details
- CVE-2025-46404 — A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lead to… HIGH 7.5 — Details
- CVE-2025-46705 — A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML assertion response can lea… HIGH 7.5 — Details
- CVE-2025-46784 — A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouvert Lasso 2.5.1. A specially crafted SAML response can lea… HIGH 7.5 — Details
- CVE-2025-47151 — A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 and 2.8.2. A specially crafted SAML response can lead to… CRITICAL 9.8 — Details
- CVE-2025-52602 — HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint request returns discoverable responses that may disclose: g… MEDIUM 4.2 — Details
📰 Security News
Top headlines from trusted sources.
- ClickFix malware attacks evolve with multi-OS support, video tutorials
— Thu, 06 Nov 2025 14:00:00 GMT - Critical Cisco UCCX flaw lets attackers run commands as root
— Thu, 06 Nov 2025 13:31:10 GMT - Sandworm hackers use data wipers to disrupt Ukraine's grain sector
— Thu, 06 Nov 2025 10:01:28 GMT - Gootloader malware is back with new tricks after 7-month break
— Wed, 05 Nov 2025 21:52:45 GMT - Hyundai AutoEver America data breach exposes SSNs, drivers licenses
— Wed, 05 Nov 2025 21:19:02 GMT - CISA warns of critical CentOS Web Panel bug exploited in attacks
— Wed, 05 Nov 2025 18:26:25 GMT
Comments
Post a Comment