Home > 취약점 정보 공유 > 보안공지
보안공지

목록

조회수 : 7,611


美 CISA 발표 주요 Exploit 정보공유(Update. 2025-10-20)2025-10-20
현재 자주 악용되고 있는 취약점 목록으로, 취약한 버전의 SW를 사용 중인 경우 긴급 패치를 권고 드립니다.
* 참조 링크 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog

cveIDvendorProjectvulnerabilityNamedateAddedshortDescriptionrequiredActiondueDate
CVE-2025-61884OracleOracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability2025-10-20Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-10
CVE-2025-33073MicrosoftMicrosoft Windows SMB Client Improper Access Control Vulnerability2025-10-20Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-10
CVE-2025-2747KenticoKentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability2025-10-20Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-10
CVE-2025-2746KenticoKentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability2025-10-20Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-10
CVE-2022-48503AppleApple Multiple Products Unspecified Vulnerability2025-10-20Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when processing web content may lead to arbitrary code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-10
출처 사이트 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog