Monthly Vuln Summary 2025-08 (15)

In-the-Wild CVE Review · 2025-08

15 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2025-57819 — 0.0 — Sangoma FreePBX — Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to… [KEV]
  • CVE-2025-7775 — 0.0 — Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. [KEV]
  • CVE-2025-48384 — 0.0 — Git Git — Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files. [KEV]
  • CVE-2024-8068 — 0.0 — Citrix Session Recording — Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an … [KEV]
  • CVE-2024-8069 — 0.0 — Citrix Session Recording — Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Att… [KEV]
  • CVE-2025-43300 — 0.0 — Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. [KEV]
  • CVE-2025-54948 — 0.0 — Trend Micro Apex One — Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code an… [KEV]
  • CVE-2025-8876 — 0.0 — N-able N-Central — N-able N-Central contains a command injection vulnerability via improper sanitization of user input. [KEV]
  • CVE-2025-8875 — 0.0 — N-able N-Central — N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. [KEV]
  • CVE-2025-8088 — 0.0 — RARLAB WinRAR — RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting mali… [KEV] [RANSOMWARE]
  • CVE-2007-0671 — 0.0 — Microsoft Office — Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as… [KEV]
  • CVE-2013-3893 — 0.0 — Microsoft Internet Explorer — Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service… [KEV]
  • CVE-2020-25078 — 0.0 — D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-li… [KEV]
  • CVE-2020-25079 — 0.0 — D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-servic… [KEV]
  • CVE-2022-40799 — 0.0 — D-Link DNR-322L — D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacte… [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.