2025年1月28日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 5 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2025-23211 Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists.

  • CVSS 9.9

新たな重大公開(CVSS 9.9)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

重大な露出リスク

CVE-2024-13448 Themerex Addons RCE

  • CVSS 9.8
  • インターネット公開 CMS への影響

新たな重大 Themerex Addons RCE(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

高リスク露出

CVE-2025-24480 A Remote Code Execution Vulnerability exists in the product and version listed above.

  • CVSS 9.3
  • リモートコード実行の露出リスク

本日のウィンドウで新たな Critical — ライフサイクル初期の露出シグナルが高まっています。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2024-13448 CVSS 9.8

The ThemeREX Addons plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'trx_addons_u...

CVE-2025-0798 CVSS 9.2

A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux.

CVE-2025-23211 CVSS 9.9

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists.

CVE-2025-24480 CVSS 9.3

A Remote Code Execution Vulnerability exists in the product and version listed above.

CVE-2025-24800 CVSS 9.3

Hyperbridge is a hyper-scalable coprocessor for verifiable, cross-chain interoperability.

Critical 公開を見る

cvelogic Threat Intelligence