Monthly Vuln Summary 2025-12 (20)

In-the-Wild CVE Review · 2025-12

20 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2025-14847 — 0.0 — MongoDB MongoDB and MongoDB Server — MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitializ… [KEV]
  • CVE-2023-52163 — 0.0 — Digiever DS-2105 Pro — Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi. [KEV]
  • CVE-2025-14733 — 0.0 — WatchGuard Firebox — WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute … [KEV] [RANSOMWARE]
  • CVE-2025-59374 — 0.0 — ASUS Live Update — ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modifie… [KEV]
  • CVE-2025-40602 — 0.0 — SonicWall SMA1000 appliance — SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices. [KEV]
  • CVE-2025-20393 — 0.0 — Cisco Multiple Products — Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbi… [KEV]
  • CVE-2025-59718 — 0.0 — Fortinet Multiple Products — Fortinet FortiOS, FortiSwitchMaster, FortiProxy, and FortiWeb contain an improper verification of cryptographic signature vulnerability that may allow an unauthenticated attacker t… [KEV]
  • CVE-2025-14611 — 0.0 — Gladinet CentreStack and Triofox — Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for pub… [KEV]
  • CVE-2025-43529 — 0.0 — Apple Multiple Products — Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This … [KEV]
  • CVE-2018-4063 — 0.0 — Sierra Wireless AirLink ALEOS — Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable… [KEV]
  • CVE-2025-14174 — 0.0 — Google Chromium — Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. Th… [KEV]
  • CVE-2025-58360 — 0.0 — OSGeo GeoServer — OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geos… [KEV]
  • CVE-2025-6218 — 0.0 — RARLAB WinRAR — RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user. [KEV]
  • CVE-2025-62221 — 0.0 — Microsoft Windows — Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2022-37055 — 0.0 — D-Link Routers — D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be end-of-life (EoL) and… [KEV]
  • CVE-2025-66644 — 0.0 — Array Networks ArrayOS AG — Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands. [KEV]
  • CVE-2025-55182 — 0.0 — Meta React Server Components — Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payload… [KEV] [RANSOMWARE]
  • CVE-2021-26828 — 0.0 — OpenPLC ScadaBR — OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_… [KEV]
  • CVE-2025-48633 — 0.0 — Android Framework — Android Framework contains an unspecified vulnerability that allows for information disclosure. [KEV]
  • CVE-2025-48572 — 0.0 — Android Framework — Android Framework contains an unspecified vulnerability that allows for privilege escalation. [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.