Monthly Vuln Summary 2025-11 (11)
In-the-Wild CVE Review · 2025-11
11 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2021-26829 —
0.0— OpenPLC ScadaBR — OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm. [KEV] - CVE-2025-61757 —
0.0— Oracle Fusion Middleware — Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager. [KEV] - CVE-2025-13223 —
0.0— Google Chromium V8 — Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption. [KEV] - CVE-2025-58034 —
0.0— Fortinet FortiWeb — Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP req… [KEV] - CVE-2025-64446 —
0.0— Fortinet FortiWeb — Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or H… [KEV] - CVE-2025-12480 —
0.0— Gladinet Triofox — Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete. [KEV] - CVE-2025-62215 —
0.0— Microsoft Windows — Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vuln… [KEV] - CVE-2025-9242 —
0.0— WatchGuard Firebox — WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code. [KEV] - CVE-2025-21042 —
0.0— Samsung Mobile Devices — Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code. [KEV] - CVE-2025-48703 —
0.0— CWP Control Web Panel — CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t… [KEV] - CVE-2025-11371 —
0.0— Gladinet CentreStack and Triofox — Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files. [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.