2025年5月12日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • TeleMessage TM SGNL が CISA KEV に新規掲載 — 実環境での悪用を確認。
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

実際の悪用を確認

CVE-2025-47729 TeleMessage TM SGNL Hidden Functionality

  • 実環境での悪用(CISA KEV)
  • CISA KEV に掲載

CISA KEV で実環境悪用が確認 — 理論上のリスクではなく、活発な脅威の動きです。

重大な露出リスク

CVE-2025-30012 Sap Supplier Relationship Management Deserialization

  • CVSS 10

新たな重大 Sap Supplier Relationship Management Deserialization(CVSS 10)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2025-44830 Engineercms Project Engineercms SQL Injection

  • CVSS 9.8

新たな重大 Engineercms Project Engineercms SQL Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2023-49641 CVSS 9.8

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities.

CVE-2025-30012 CVSS 10

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthent...

CVE-2025-30436 CVSS 9.1

This issue was addressed by restricting options offered on a locked device.

CVE-2025-30448 CVSS 9.1

This issue was addressed with additional entitlement checks.

CVE-2025-3659 CVSS 9.4

Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families: * Digi PortServe...

CVE-2025-44022 CVSS 9.8

An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.

CVE-2025-44830 CVSS 9.8

EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.

CVE-2025-45779 CVSS 9.8

Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.

CVE-2025-47682 CVSS 9.3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notific...

Critical 公開を見る

cvelogic Threat Intelligence