Monthly Vuln Summary 2025-10 (31)
In-the-Wild CVE Review · 2025-10
31 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2025-41244 —
0.0— Broadcom VMware Aria Operations and VMware Tools — Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having ac… [KEV] - CVE-2025-24893 —
0.0— XWiki Platform — XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch. [KEV] - CVE-2025-6204 —
0.0— Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code. [KEV] - CVE-2025-6205 —
0.0— Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application. [KEV] - CVE-2025-54236 —
0.0— Adobe Commerce and Magento — Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API. [KEV] - CVE-2025-59287 —
0.0— Microsoft Windows — Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. [KEV] - CVE-2025-61932 —
0.0— Motex LANSCOPE Endpoint Manager — Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending speci… [KEV] - CVE-2022-48503 —
0.0— Apple Multiple Products — Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impact… [KEV] - CVE-2025-2746 —
0.0— Kentico Xperience CMS — Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. [KEV] - CVE-2025-2747 —
0.0— Kentico Xperience CMS — Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects. [KEV] - CVE-2025-33073 —
0.0— Microsoft Windows — Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious sc… [KEV] - CVE-2025-61884 —
0.0— Oracle E-Business Suite — Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable with… [KEV] [RANSOMWARE] - CVE-2025-54253 —
0.0— Adobe Experience Manager (AEM) Forms — Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution. [KEV] - CVE-2025-47827 —
0.0— IGEL IGEL OS — IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signatur… [KEV] - CVE-2025-24990 —
0.0— Microsoft Windows — Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulne… [KEV] - CVE-2025-59230 —
0.0— Microsoft Windows — Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges local… [KEV] - CVE-2016-7836 —
0.0— SKYSEA Client View — SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the manage… [KEV] - CVE-2021-43798 —
0.0— Grafana Labs Grafana — Grafana contains a path traversal vulnerability that could allow access to local files. [KEV] - CVE-2025-27915 —
0.0— Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS… [KEV] - CVE-2021-22555 —
0.0— Linux Kernel — Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. [KEV] - CVE-2010-3962 —
0.0— Microsoft Internet Explorer — Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) an… [KEV] - CVE-2021-43226 —
0.0— Microsoft Windows — Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. [KEV] [RANSOMWARE] - CVE-2013-3918 —
0.0— Microsoft Windows — Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability b… [KEV] - CVE-2011-3402 —
0.0— Microsoft Windows — Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute … [KEV] - CVE-2010-3765 —
0.0— Mozilla Multiple Products — Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors rela… [KEV] - CVE-2025-61882 —
0.0— Oracle E-Business Suite — Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via H… [KEV] [RANSOMWARE] - CVE-2014-6278 —
0.0— GNU GNU Bash — GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment. [KEV] - CVE-2017-1000353 —
0.0— Jenkins Jenkins — Jenkins contains a remote code execution vulnerability. This vulnerability that could allowed attackers to transfer a serialized Java SignedObject object to the remoting-based Jenk… [KEV] - CVE-2015-7755 —
0.0— Juniper ScreenOS — Juniper ScreenOS contains an improper authentication vulnerability that could allow unauthorized remote administrative access to the device. [KEV] - CVE-2025-21043 —
0.0— Samsung Mobile Devices — Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so which allows remote attackers to execute arbitrary code. [KEV] - CVE-2025-4008 —
0.0— Smartbedded Meteobridge — Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (r… [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.