Weekly Board Brief

Generated: 2025-11-18T01:12:19Z
Added 2000 Removed 2000 Modified 0

ATT&CK Tactics (hints)

Privilege Escalation: 49 Execution: 38 Initial Access: 35 Command and Control: 12

Top Vendors Observed

github.com: 58 msrc.microsoft.com: 16 plugins.trac.wordpress.org: 12 talosintelligence.com: 9 bugzilla.mozilla.org: 8 themeforest.net: 7 corp.mediatek.com: 6 usom.gov.tr: 4

Top Prioritized Items

CVEKEVCVSSEPSSPriorityATT&CKDescription
CVE-2025-61882KEV9.80.00%8.36Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versi
CVE-2025-59287KEV9.80.00%8.36T1190Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over a network.
CVE-2025-345010.00.00%7.0An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an
CVE-2025-6216810.00.00%7.0Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling
CVE-2025-24990KEV7.80.00%6.96Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. T
CVE-2025-59230KEV7.80.00%6.96Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVE-2025-609579.90.00%6.93T1059.004OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers t
CVE-2025-448239.90.00%6.93Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.ph
CVE-2025-619139.90.00%6.93T1105Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadF
CVE-2025-115399.90.00%6.93T1203Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the
CVE-2025-603069.90.00%6.93code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and per
CVE-2025-497089.90.00%6.93Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
CVE-2025-553159.90.00%6.93Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized attacker to bypass a s
CVE-2025-342679.90.00%6.93Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability
CVE-2025-626459.90.00%6.93The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker to obtain a token wit
CVE-2025-94859.80.00%6.86The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptographic Signature in vers
CVE-2023-498869.80.00%6.86T1190IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java de
CVE-2025-575159.80.00%6.86T1059.005, T1190A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL c
CVE-2025-06039.80.00%6.86T1059.005, T1190Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emerg
CVE-2025-520219.80.00%6.86T1059.005, T1190A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET
CVE-2025-114189.80.00%6.86T1068A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/A
CVE-2025-114239.80.00%6.86A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performi
CVE-2025-105879.80.00%6.86T1059.005, T1190The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and includi
CVE-2025-105869.80.00%6.86T1059.005, T1190The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and includin
CVE-2025-75269.80.00%6.86T1105The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renam
CVE-2025-76349.80.00%6.86The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versio
CVE-2025-115229.80.00%6.86The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions
CVE-2025-350509.80.00%6.86T1190Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attac
CVE-2025-350519.80.00%6.86T1190Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, una
CVE-2025-592469.80.00%6.86Azure Entra ID Elevation of Privilege Vulnerability

Priority = 1.5×KEV + 0.7×CVSS + 1.2×EPSS. ATT&CK entries are heuristic hints.