2025年7月23日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2025-41687 An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management...

  • CVSS 9.8

新たな重大公開(CVSS 9.8)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

高リスク露出

CVE-2018-25114 Oscommerce Online Merchant RCE

  • CVSS 9.3
  • リモートコード実行の露出リスク

新高危 Oscommerce Online Merchant RCE — 公開後 72 時間以内のエクスプロイト出現とスキャナ動向に注意。

高リスク露出

CVE-2015-10141 An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and ear...

  • CVSS 9.3

本日のウィンドウで新たな Critical — ライフサイクル初期の露出シグナルが高まっています。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2015-10141 CVSS 9.3

An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging extension develope...

CVE-2016-15044 CVSS 9.3

A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data...

CVE-2017-20198 CVSS 9.3

The Marathon UI in DC/OS < 1.9.0 allows unauthenticated users to deploy arbitrary Docker containers.

CVE-2018-25114 CVSS 9.3

A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and...

CVE-2022-4978 CVSS 9.3

Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, w...

CVE-2025-40599 CVSS 9.1

An authenticated arbitrary file upload vulnerability exists in the SMA 100 series web management interface.

CVE-2025-41687 CVSS 9.8

An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full access on the affected...

CVE-2025-54294 CVSS 9.3

A SQLi vulnerability in Komento component 4.0.0-4.0.7for Joomla was discovered.

CVE-2025-54455 CVSS 9.1

Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue affects Mag...

CVE-2025-8070 CVSS 9.2

The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability.

Critical 公開を見る

cvelogic Threat Intelligence