2025年11月5日 サイバー脅威インテリジェンス

日次の脆弱性動向:KEV 追加、公開 exploit、重大開示、EPSS リスクの変化。

日次サマリー

  • 10 件の新規 Critical 公開 — 露出サービスのパッチ状況を確認してください。

本日の重点脅威

最優先の 3 件の変化 — アナリストによる短評。CVE ダンプではありません。

重大な露出リスク

CVE-2025-55343 Quipux SQL Injection

  • CVSS 9.9

新たな重大 Quipux SQL Injection(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2025-63601 Snipeitapp Snipe-it RCE

  • CVSS 9.9
  • リモートコード実行の露出リスク

新たな重大 Snipeitapp Snipe-it RCE(CVSS 9.9)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

重大な露出リスク

CVE-2025-61304 Dynatrace Activegate Ping Extension Command Injection

  • CVSS 9.8

新たな重大 Dynatrace Activegate Ping Extension Command Injection(CVSS 9.8)— 公開直後のウィンドウ。成熟した悪用チェーンの前にインターネットスキャンが先行しがちです。

実際の悪用

CISA KEV — 実環境での悪用が確認

本ダイジェストではこのカテゴリに該当なし。

KEV 新規掲載を見る

エクスプロイト・PoC

本ダイジェストではこのカテゴリに該当なし。

新規エクスプロイト紐づけを見る

悪用動態

本ダイジェストではこのカテゴリに該当なし。

EPSS 上昇を見る

新規 Critical 公開

CVE-2025-20354 CVSS 9.8

新たな重大 Cisco Unified Contact Center Express の露出が公開。

CVE-2025-20358 CVSS 9.4

新たな重大 Cisco Unified Contact Center Express の露出が公開。

CVE-2025-45378 CVSS 9.1

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell.

CVE-2025-46364 CVSS 9.1

Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI Escape Vulnerabi...

CVE-2025-55343 CVSS 9.9

Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_depe_codi, busqued...

CVE-2025-56231 CVSS 9.1

Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass u...

CVE-2025-61304 CVSS 9.8

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.

CVE-2025-63334 CVSS 9.8

PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php co...

CVE-2025-63416 CVSS 9.1

** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 202...

CVE-2025-63601 CVSS 9.9

Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to upload a malicious...

Critical 公開を見る

cvelogic Threat Intelligence