[Ransomware Exploitation: Unknown] TeleMessage TM SGNL has a hidden functionality vulnerability, where the archiving backend retains plaintext copies of messages from TM SGNL application users.
[Affected Platforms] TeleMessage archiving backend versions before 2025-05-05
CVE-2025-32709】Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (CVSS v3.1: 7.8)
[Ransomware Exploitation: Unknown] Microsoft Windows WinSock Ancillary Function Driver has a use-after-free vulnerability, allowing authorized attackers to elevate privileges to system administrator.
CVE-2025-30397】Microsoft Windows Scripting Engine Type Confusion Vulnerability (CVSS v3.1: 7.5)
[Ransomware Exploitation: Unknown] Microsoft Windows Scripting Engine has a type confusion vulnerability, allowing unauthorized attackers to execute code on the network via specially crafted URLs.
CVE-2025-32706】Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability (CVSS v3.1: 7.8)
[Ransomware Exploitation: Unknown] Microsoft Windows Common Log File System driver has a heap-based buffer overflow vulnerability, allowing authorized attackers to elevate privileges locally.
CVE-2025-32701】Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability (CVSS v3.1: 7.8)
[Ransomware Exploitation: Unknown] Microsoft Windows Common Log File System driver has a use-after-free vulnerability, allowing authorized attackers to elevate privileges locally.
CVE-2025-30400】Microsoft Windows DWM Core Library Use-After-Free Vulnerability (CVSS v3.1: 7.8)
[Ransomware Exploitation: Unknown] Microsoft Windows DWM Core Library has a use-after-free vulnerability, allowing authorized attackers to elevate privileges locally.
[Ransomware Exploitation: Unknown] SAP NetWeaver Visual Composer Metadata Uploader has a deserialization vulnerability, allowing privileged attackers to deserialize untrusted or malicious content, compromising the confidentiality, integrity, and availability of the host system.
[Affected Platforms] SAP NetWeaver (Visual Composer development server) VCFRAMEWORK 7.50
CVE-2024-12987】DrayTek Vigor Routers OS Command Injection Vulnerability (CVSS v3.1: 9.8)
[Ransomware Exploitation: Unknown] DrayTek Vigor2960, Vigor300B, and Vigor3900 routers have an OS command injection vulnerability, originating from an unknown function in the Web management interface apmcfgupload file.
[Affected Platforms] Please refer to the official list of affected versions
[Ransomware Exploitation: Unknown] Google Chromium has an insufficient policy enforcement vulnerability, allowing remote attackers to leak cross-origin data via specially crafted HTML pages.
[Affected Platforms] Please refer to the official list of affected versions