Aggregator
CVE-2025-47289 | CE-PhoenixCart up to 1.0.9.9/1.1.0.2/1.1.0.3 testimonial description cross site scripting (GHSA-98qq-m8qj-vvgj)
CVE-2025-48494 | Forceu Gokapi up to 1.x cross site scripting (GHSA-95rc-wc32-gm53)
CVE-2025-0819 | ARM Bifrost GPU Kernel Driver up to r49p3/r51p0 use after free
CVE-2025-0073 | ARM Valhall GPU Kernel Driver use after free (r54p0)
CVE-2025-48955 | Erudika para up to 1.50.7 log file (EUVD-2025-16635)
CVE-2025-48495 | Forceu Gokapi up to 1.x API Page cross site scripting
CVE-2025-48957 | AstrBotDevs AstrBot up to 3.5.12 cmd_config.json path traversal
CVE-2025-29785 | quic-go 0.50.0 uncaught exception (ID 4981)
CVE-2025-47272 | CE-PhoenixCart prior 1.1.0.3 missing authentication (GHSA-62qj-pvwm-h8cv)
CISA Adds Five Known Exploited Vulnerabilities to Catalog
CISA added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2021-32030 ASUS Routers Improper Authentication Vulnerability
- CVE-2023-39780 ASUS RT-AX55 Routers OS Command Injection Vulnerability
- CVE-2024-56145 Craft CMS Code Injection Vulnerability
- CVE-2025-3935 ConnectWise ScreenConnect Improper Authentication Vulnerability
- CVE-2025-35939 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Please share your thoughts with us through our anonymous survey. We appreciate your feedback.
Securing APIs Protecting Backbone of Modern Applications
As modern applications increasingly depend on APIs to drive everything from mobile banking to healthcare systems, a growing security crisis is emerging across the digital landscape, highlighting the critical importance of securing APIs. New data reveals that API security incidents have more than doubled in just one year, with 37% of organizations reporting breaches in […]
The post Securing APIs Protecting Backbone of Modern Applications appeared first on Cyber Security News.