NVD disclosure day

Published threat advisories for February 3, 2025

CVE advisoryKnown Exploit

CVE-2023-52163

Digiever DS-2105 Pro Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Digiever DS-2105 Pro devices are impacted by a command injection vulnerability. Attackers can execute arbitrary commands, potentially leading to data compromise and unauthorized access. This affects unsupported products, posing a risk to organizations.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2025-25181

Advantive VeraCore SQL Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A SQL injection vulnerability in Advantive VeraCore allows remote attackers to execute arbitrary SQL commands. This could lead to unauthorized access to sensitive data and disruption of business operations. Organizations using affected software face significant business risk and potential data compromise.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-57968

Advantive VeraCore File Upload Risk

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Advantive VeraCore software has a vulnerability allowing authenticated users to upload files to unintended, accessible folders. This impacts organizations by potentially exposing sensitive data and systems to unauthorized access or modification. The realistic business risk involves compromised data integrity and confid

• CISA KEV