Home > 취약점 정보 공유 > 보안공지
보안공지

목록

조회수 : 955


美 CISA 발표 주요 Exploit 정보공유(Update. 2025-10-30)2025-10-30
현재 자주 악용되고 있는 취약점 목록으로, 취약한 버전의 SW를 사용 중인 경우 긴급 패치를 권고 드립니다.
* 참조 링크 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog

cveIDvendorProjectvulnerabilityNamedateAddedshortDescriptionrequiredActiondueDate
CVE-2025-24893XWikiXWiki Platform Eval Injection Vulnerability2025-10-30XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-20
CVE-2025-41244BroadcomBroadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability2025-10-30Broadcom VMware Aria Operations and VMware Tools contain a privilege defined with unsafe actions vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploit this vulnerability to escalate privileges to root on the same VM.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2025-11-20
출처 사이트 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog