2025年7月16日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Pivotx:公開エクスプロイトまたは PoC が関連付けられました (cross-site scripting)
  • WordPress プラグインの RCE/悪用動向:本日 2 件の CVE をフラグ。
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

悪用活動を確認

CVE-2024-11605 Wp-publications Project Wp-publications XSS

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け
  • インターネット公開 CMS への影響

WordPress プラグインの露出と公開エクスプロイト — PoC 流通後はインターネット公開 CMS への大規模標的化が一般的です。

悪用活動を確認

CVE-2024-58258 Sugarcrm SSRF

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け

Sugarcrm SSRF に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。

重大な露出リスク

CVE-2025-20337 Cisco Identity Services Engine Injection

  • CVSS 10
  • ネットワーク境界 / SD-WAN への影響

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

Cross Site Scripting vulnerability in PivotX CMS v.3.0.0 RC 3 allows a remote attacker to execute arbitrary code via the subtitle field.

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX.

SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.

A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to...

A directory traversal vulnerability was discovered in White Star Software Protop version 4.4.2-2024-11-27, specifically in the /pt3upd/ e...

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

CVE-2025-6563 悪用

A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2.

CVE-2025-1550 悪用

The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious...

The wp-publications WordPress plugin through 1.2 does not escape filenames before outputting them back in the page, which could allow hig...

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2025-34117 CVSS 9.3

A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 due...

CVE-2025-34121 CVSS 9.3

An unauthenticated arbitrary file upload vulnerability exists in Idera Up.Time Monitoring Station versions up to and including 7.2.

CVE-2025-34125 CVSS 9.3

An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D-Link DSP-W110A1...

CVE-2025-34127 CVSS 9.3

A stack-based buffer overflow exists in Achat v0.150 in its default configuration.

CVE-2025-34132 CVSS 9.3

A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_20200207 via the...

CVE-2025-34300 CVSS 10

A template injection vulnerability exists in Sawtooth Software’s Lighthouse Studio versions prior to 9.16.14 via the ciwweb.pl http://ciw...

CVE-2025-53937 CVSS 9.4

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions.

CVE-2025-5396 CVSS 9.8

The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0.

CVE-2025-7712 CVSS 9.1

The Madara - Core plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp_manga_...

Critical 公開を見る

cvelogic Threat Intelligence