Monthly Vuln Summary 2025-08 (15)
In-the-Wild CVE Review · 2025-08
15 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2025-57819 —
0.0— Sangoma FreePBX — Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to… [KEV] - CVE-2025-7775 —
0.0— Citrix NetScaler — Citrix NetScaler ADC and NetScaler Gateway contain a memory overflow vulnerability that could allow for remote code execution and/or denial of service. [KEV] - CVE-2025-48384 —
0.0— Git Git — Git contains a link following vulnerability that stems from Git’s inconsistent handling of carriage return characters in configuration files. [KEV] - CVE-2024-8068 —
0.0— Citrix Session Recording — Citrix Session Recording contains an improper privilege management vulnerability that could allow for privilege escalation to NetworkService Account access. An attacker must be an … [KEV] - CVE-2024-8069 —
0.0— Citrix Session Recording — Citrix Session Recording contains a deserialization of untrusted data vulnerability that allows limited remote code execution with privilege of a NetworkService Account access. Att… [KEV] - CVE-2025-43300 —
0.0— Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. [KEV] - CVE-2025-54948 —
0.0— Trend Micro Apex One — Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code an… [KEV] - CVE-2025-8876 —
0.0— N-able N-Central — N-able N-Central contains a command injection vulnerability via improper sanitization of user input. [KEV] - CVE-2025-8875 —
0.0— N-able N-Central — N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. [KEV] - CVE-2025-8088 —
0.0— RARLAB WinRAR — RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting mali… [KEV] [RANSOMWARE] - CVE-2007-0671 —
0.0— Microsoft Office — Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as… [KEV] - CVE-2013-3893 —
0.0— Microsoft Internet Explorer — Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service… [KEV] - CVE-2020-25078 —
0.0— D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-li… [KEV] - CVE-2020-25079 —
0.0— D-Link DCS-2530L and DCS-2670L Devices — D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-servic… [KEV] - CVE-2022-40799 —
0.0— D-Link DNR-322L — D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacte… [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.