2025年7月28日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • Cisco Identity Services Engine:本日 2 件が CISA KEV に新規掲載。
  • Xwiki:公開エクスプロイトまたは PoC が関連付けられました (SQL injection)
  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

実際の悪用を確認

CVE-2023-2533 PaperCut NG/MF Cross-Site Request Forgery (CSRF)

  • 実環境での悪用(CISA KEV)
  • CISA KEV に掲載

PaperCut NG/MF CSRF は CISA KEV に掲載 — 実環境での悪用が確認されています。掲載中は継続的な標的化が想定されます。

悪用活動を確認

CVE-2024-0737 A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1.

  • 公開エクスプロイトまたは PoC あり
  • 悪用活動が関連付け

Xlightftpd Xlight Ftp Server DoS に公開エクスプロイトまたは PoC が関連 — 日和見的スキャンと続く標的型活動を想定してください。

重大な露出リスク

CVE-2025-54419 A SAML library not dependent on any frameworks that runs in Node.

  • CVSS 10

新たな重大公開(CVSS 10)— 深刻度が高く、エクスプロイト出現前の認知ウィンドウが短いです。

実際の悪用

CISA KEV — 実環境での悪用が確認

PaperCut NG/MF Cross-Site Request Forgery (CSRF)

KEV 新規掲載を見る

エクスプロイト・PoC

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.

A cross-site scripting (XSS) vulnerability in the component /blog/blogpost/add of Mezzanine CMS v6.1.0 allows attackers to execute arbitr...

CVE-2025-6018 悪用

A Local Privilege Escalation (LPE) vulnerability has been discovered in pam-config within Linux Pluggable Authentication Modules (PAM).

CVE-2024-0737 悪用

A vulnerability classified as problematic was found in Xlightftpd Xlight FTP Server 1.1.

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2025-30125 CVSS 9.8

An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices.

CVE-2025-30133 CVSS 9.8

An issue was discovered on IROAD Dashcam FX2 devices.

CVE-2025-53695 CVSS 9.4

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root'...

CVE-2025-53696 CVSS 9.3

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware.

CVE-2025-54298 CVSS 9.4

A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.

CVE-2025-54299 CVSS 9.4

A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.

CVE-2025-54418 CVSS 9.8

CodeIgniter is a PHP full-stack web framework.

CVE-2025-54419 CVSS 10

A SAML library not dependent on any frameworks that runs in Node.

CVE-2025-54426 CVSS 9.9

Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate.

CVE-2025-54428 CVSS 9.8

RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessible language.

Critical 公開を見る

cvelogic Threat Intelligence