Weekly Board Brief

Generated: 2025-10-01T19:08:38Z
Added 2000 Removed 0 Modified 0

ATT&CK Tactics (hints)

Execution: 41 Initial Access: 39 Privilege Escalation: 35 Command and Control: 6

Top Vendors Observed

github.com: 47 patchstack.com: 24 talosintelligence.com: 23 android.googlesource.com: 7 plugins.trac.wordpress.org: 6 bugzilla.mozilla.org: 6 gist.github.com: 6 gitee.com: 5

Top Prioritized Items

CVEKEVCVSSEPSSPriorityATT&CKDescription
CVE-2025-7775KEV9.80.00%8.36Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScale
CVE-2025-57819KEV9.80.00%8.36T1059.005, T1190FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitize
CVE-2025-43300KEV8.80.00%7.66T1068An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 a
CVE-2025-5056710.00.00%7.0T1059.005, T1190, T1203Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replace() with the depreca
CVE-2025-4814810.00.00%7.0T1190Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce allows Using Malicious Files.
CVE-2025-5357710.00.00%7.0T1203Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS allows Remote Code Inclusion. This issue affects
CVE-2022-3149110.00.00%7.0T1203Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote at
CVE-2025-4938710.00.00%7.0T1190Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms allows Upload a W
CVE-2025-481699.90.00%6.93T1203Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine allows Remote Code Inclusion. This issue a
CVE-2025-532139.90.00%6.93T1190Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Conditional Shipping all
CVE-2025-540499.90.00%6.93Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for
CVE-2025-532519.90.00%6.93T1190Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP allows Upload a Web Shell to a Web Server.This issue affec
CVE-2025-580489.90.00%6.93T1190Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymente
CVE-2025-581599.90.00%6.93T1203, T1190WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by
CVE-2025-311009.90.00%6.93T1190Unrestricted Upload of File with Dangerous Type vulnerability in Mojoomla School Management allows Upload a Web Shell to a Web Server.This i
CVE-2025-317159.80.00%6.86In vowifi service, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege
CVE-2025-555919.80.00%6.86TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac parameter in the formMapD
CVE-2025-67589.80.00%6.86The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the 'imic_agent_registe
CVE-2025-87239.80.00%6.86T1203The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication and insufficient san
CVE-2025-543369.80.00%6.86In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed by any digit string,
CVE-2025-552949.80.00%6.86screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue. When user-controlle
CVE-2024-443739.80.00%6.86T1105A Path Traversal vulnerability in AllSky v2023.05.01_04 allows an unauthenticated attacker to create a webshell and remote code execution vi
CVE-2025-553069.80.00%6.86GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX FX backend where API
CVE-2025-515439.80.00%6.86An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /administrator/auth/reset_p
CVE-2025-541439.80.00%6.86Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the p
CVE-2025-550319.80.00%6.86Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An attacker within Bluetoo
CVE-2025-80429.80.00%6.86Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefo
CVE-2025-91799.80.00%6.86An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is also heavily sandboxed
CVE-2025-91879.80.00%6.86Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption and we presume that w
CVE-2025-532999.80.00%6.86T1190Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer allows Object Injection. This issue affec

Priority = 1.5×KEV + 0.7×CVSS + 1.2×EPSS. ATT&CK entries are heuristic hints.