KEV 2025

180 CISA Known Exploited Vulnerabilities from 2025

CVE-2025-32975

Quest KACE SMA — Unauthenticated SSO Authentication Bypass Enabling Full Administrative Takeover

CVSS 10

CVE-2025-32432

Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability

CVSS 10

CVE-2025-52691

SmarterTools SmarterMail — SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability

CVSS 10

CVE-2025-37164

Hewlett Packard Enterprise (HPE) OneView — Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

CVSS 10

CVE-2025-20393

Cisco Multiple Products — Cisco Multiple Products Improper Input Validation Vulnerability

CVSS 10

CVE-2025-55182

Meta React Server Components — Meta React Server Components Remote Code Execution Vulnerability

CVSS 10

CVE-2025-54253

Adobe Experience Manager (AEM) Forms — Adobe Experience Manager Forms Code Execution Vulnerability

CVSS 10

CVE-2025-10035

Fortra GoAnywhere MFT — Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability

CVSS 10

CVE-2025-43300

Apple iOS, iPadOS, and macOS — Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability

CVSS 10

CVE-2025-20281

Cisco Identity Services Engine — Cisco Identity Services Engine Injection Vulnerability

CVSS 10

CVE-2025-20337

Cisco Identity Services Engine — Cisco Identity Services Engine Injection Vulnerability

CVSS 10

CVE-2025-47812

Wing FTP Server Wing FTP Server — Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability

CVSS 10

CVE-2025-32433

Erlang Erlang/OTP — Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability

CVSS 10

CVE-2025-34028

Commvault Command Center — Commvault Command Center Path Traversal Vulnerability

CVSS 10

CVE-2025-31324

SAP NetWeaver — SAP NetWeaver Unrestricted File Upload Vulnerability

CVSS 10

CVE-2025-24201

Apple Multiple Products — Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

CVSS 10

CVE-2025-24085

Apple Multiple Products — Apple Multiple Products Use-After-Free Vulnerability

CVSS 10

CVE-2025-68613

n8n n8n — n8n Improper Control of Dynamically-Managed Code Resources Vulnerability

CVSS 9.9

CVE-2025-49113

Roundcube Webmail — RoundCube Webmail Deserialization of Untrusted Data Vulnerability

CVSS 9.9

CVE-2025-20333

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

CVSS 9.9

CVE-2025-24016

Wazuh Wazuh Server — Wazuh Server Deserialization of Untrusted Data Vulnerability

CVSS 9.9

CVE-2025-53521

F5 BIG-IP APM — Remote Code Execution via Malicious Traffic to Access Policy Virtual Server

CVSS 9.8

CVE-2025-54068

Laravel Livewire — Laravel Livewire Code Injection Vulnerability

CVSS 9.8

CVE-2025-26399

SolarWinds Web Help Desk — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2025-11953

React Native Community CLI — React Native Community CLI OS Command Injection Vulnerability

CVSS 9.8

CVE-2025-40551

SolarWinds Web Help Desk — SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2025-14733

WatchGuard Firebox — WatchGuard Firebox Out of Bounds Write Vulnerability

CVSS 9.8

CVE-2025-59374

ASUS Live Update — ASUS Live Update Embedded Malicious Code Vulnerability

CVSS 9.8

CVE-2025-59718

Fortinet Multiple Products — Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability

CVSS 9.8

CVE-2025-14611

Gladinet CentreStack and Triofox — Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability

CVSS 9.8

CVE-2025-61757

Oracle Fusion Middleware — Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability

CVSS 9.8

CVE-2025-64446

Fortinet FortiWeb — Fortinet FortiWeb Path Traversal Vulnerability

CVSS 9.8

CVE-2025-9242

WatchGuard Firebox — WatchGuard Firebox Out-of-Bounds Write Vulnerability

CVSS 9.8

CVE-2025-24893

XWiki Platform — XWiki Platform Eval Injection Vulnerability

CVSS 9.8

CVE-2025-59287

Microsoft Windows — Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2025-61932

LANSCOPE Endpoint Manager — Unauthenticated Remote Code Execution via Spoofed Communication Channel, Exploited by Chinese APT Bronze Butler

CVSS 9.8

CVE-2025-2746

Kentico Xperience CMS — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVSS 9.8

CVE-2025-2747

Kentico Xperience CMS — Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability

CVSS 9.8

CVE-2025-61882

Oracle E-Business Suite — Oracle E-Business Suite Unspecified Vulnerability

CVSS 9.8

CVE-2025-10585

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 9.8

CVE-2025-57819

Sangoma FreePBX — Sangoma FreePBX Authentication Bypass Vulnerability

CVSS 9.8

CVE-2025-7775

Citrix NetScaler — Citrix NetScaler Memory Overflow Vulnerability

CVSS 9.8

CVE-2025-53770

Microsoft SharePoint — Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

CVSS 9.8

CVE-2025-25257

Fortinet FortiWeb — Fortinet FortiWeb SQL Injection Vulnerability

CVSS 9.8

CVE-2025-6543

Citrix NetScaler ADC and Gateway — Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability

CVSS 9.8

CVE-2025-4632

Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server Path Traversal Vulnerability

CVSS 9.8

CVE-2025-32756

Fortinet Multiple Products — Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability

CVSS 9.8

CVE-2025-3248

Langflow Langflow — Langflow Missing Authentication Vulnerability

CVSS 9.8

CVE-2025-42599

Qualitia Active! Mail — Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

CVSS 9.8

CVE-2025-31200

Apple Multiple Products — Apple Multiple Products Memory Corruption Vulnerability

CVSS 9.8

CVE-2025-31201

Apple Multiple Products — Apple Multiple Products Arbitrary Read and Write Vulnerability

CVSS 9.8

CVE-2025-31161

CrushFTP CrushFTP — CrushFTP Authentication Bypass Vulnerability

CVSS 9.8

CVE-2025-24813

Apache Tomcat — Apache Tomcat Path Equivalence Vulnerability

CVSS 9.8

CVE-2025-1316

Edimax IC-7100 IP Camera — Edimax IC-7100 IP Camera OS Command Injection Vulnerability

CVSS 9.8

CVE-2025-23006

SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliances Deserialization Vulnerability

CVSS 9.8

CVE-2025-54948

Trend Micro Apex One — Trend Micro Apex One OS Command Injection Vulnerability

CVSS 9.4

CVE-2025-32463

Sudo Sudo — Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability

CVSS 9.3

CVE-2025-2775

SysAid SysAid On-Prem — SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

CVSS 9.3

CVE-2025-2776

SysAid SysAid On-Prem — SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

CVSS 9.3

CVE-2025-22224

VMware ESXi and Workstation — VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

CVSS 9.3

CVE-2025-12480

Gladinet Triofox — Gladinet Triofox Improper Access Control Vulnerability

CVSS 9.1

CVE-2025-6205

Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability

CVSS 9.1

CVE-2025-54236

Adobe Commerce and Magento — Adobe Commerce and Magento Improper Input Validation Vulnerability

CVSS 9.1

CVE-2025-42999

SAP NetWeaver — SAP NetWeaver Deserialization Vulnerability

CVSS 9.1

CVE-2025-0108

Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

CVSS 9.1

CVE-2025-48703

CWP Control Web Panel — CWP Control Web Panel OS Command Injection Vulnerability

CVSS 9

CVE-2025-5086

Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso Deserialization of Untrusted Data Vulnerability

CVSS 9

CVE-2025-53690

Sitecore Multiple Products — Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability

CVSS 9

CVE-2025-54309

CrushFTP CrushFTP — CrushFTP Unprotected Alternate Channel Vulnerability

CVSS 9

CVE-2025-30406

Gladinet CentreStack — Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

CVSS 9

CVE-2025-22457

Ivanti Connect Secure, Policy Secure, and ZTA Gateways — Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

CVSS 9

CVE-2025-0282

Ivanti Connect Secure, Policy Secure, and ZTA Gateways — Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

CVSS 9

CVE-2025-31277

Apple Multiple Products — Apple Multiple Products Buffer Overflow Vulnerability

CVSS 8.8

CVE-2025-68645

Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability

CVSS 8.8

CVE-2025-8110

Gogs Gogs — Gogs Path Traversal Vulnerability

CVSS 8.8

CVE-2025-43529

Apple Multiple Products — Apple Multiple Products Use-After-Free WebKit Vulnerability

CVSS 8.8

CVE-2025-14174

Google Chromium — Google Chromium Out of Bounds Memory Access Vulnerability

CVSS 8.8

CVE-2025-13223

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.8

CVE-2025-21042

Samsung Mobile Devices — Samsung Mobile Devices Out-of-Bounds Write Vulnerability

CVSS 8.8

CVE-2025-33073

Microsoft Windows — Microsoft Windows SMB Client Improper Access Control Vulnerability

CVSS 8.8

CVE-2025-21043

Samsung Mobile Devices — Samsung Mobile Devices Out-of-Bounds Write Vulnerability

CVSS 8.8

CVE-2025-4008

Smartbedded Meteobridge — Smartbedded Meteobridge Command Injection Vulnerability

CVSS 8.8

CVE-2025-48543

Android Runtime — Android Runtime Use-After-Free Vulnerability

CVSS 8.8

CVE-2025-8876

N-able N-Central — N-able N-Central Command Injection Vulnerability

CVSS 8.8

CVE-2025-8088

RARLAB WinRAR — RARLAB WinRAR Path Traversal Vulnerability

CVSS 8.8

CVE-2025-49704

Microsoft SharePoint — Microsoft SharePoint Code Injection Vulnerability

CVSS 8.8

CVE-2025-6558

Google Chromium — Google Chromium ANGLE and GPU Improper Input Validation Vulnerability

CVSS 8.8

CVE-2025-33053

Microsoft Windows — Microsoft Windows External Control of File Name or Path Vulnerability

CVSS 8.8

CVE-2025-5419

Google Chromium V8 — Google Chromium V8 Out-of-Bounds Read and Write Vulnerability

CVSS 8.8

CVE-2025-3928

Commvault Web Server — Commvault Web Server Unspecified Vulnerability

CVSS 8.8

CVE-2025-0994

Trimble Cityworks — Trimble Cityworks Deserialization Vulnerability

CVSS 8.8

CVE-2025-21479

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

CVSS 8.6

CVE-2025-21480

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability

CVSS 8.6

CVE-2025-30154

reviewdog action-setup GitHub Action — reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

CVSS 8.6

CVE-2025-30066

tj-actions changed-files GitHub Action — tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

CVSS 8.6

CVE-2025-2783

Google Chromium Mojo — Google Chromium Mojo Sandbox Escape Vulnerability

CVSS 8.3

CVE-2025-58360

OSGeo GeoServer — OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability

CVSS 8.2

CVE-2025-22225

VMware ESXi — VMware ESXi Arbitrary Write Vulnerability

CVSS 8.2

CVE-2025-24989

Microsoft Power Pages — Microsoft Power Pages Improper Access Control Vulnerability

CVSS 8.2

CVE-2025-40536

SolarWinds Web Help Desk — SolarWinds Web Help Desk Security Control Bypass Vulnerability

CVSS 8.1

CVE-2025-6554

Google Chromium V8 — Google Chromium V8 Type Confusion Vulnerability

CVSS 8.1

CVE-2025-3935

ConnectWise ScreenConnect — ConnectWise ScreenConnect Improper Authentication Vulnerability

CVSS 8.1

CVE-2025-27363

FreeType FreeType — FreeType Out-of-Bounds Write Vulnerability

CVSS 8.1

CVE-2025-24472

Fortinet FortiOS and FortiProxy — Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

CVSS 8.1

CVE-2025-6204

Dassault Systèmes DELMIA Apriso — Dassault Systèmes DELMIA Apriso Code Injection Vulnerability

CVSS 8

CVE-2025-48384

Git Git — Git Link Following Vulnerability

CVSS 8

CVE-2025-23209

Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability

CVSS 8

CVE-2025-60710

Windows Host Process for Tasks (taskhostw.exe) — Symbolic Link Abuse Leading to SYSTEM Privilege Escalation

CVSS 7.8

CVE-2025-43510

Apple Multiple Products — Apple Multiple Products Improper Locking Vulnerability

CVSS 7.8

CVE-2025-6218

RARLAB WinRAR — RARLAB WinRAR Path Traversal Vulnerability

CVSS 7.8

CVE-2025-62221

Microsoft Windows — Microsoft Windows Use After Free Vulnerability

CVSS 7.8

CVE-2025-48572

Android Framework — Android Framework Privilege Escalation Vulnerability

CVSS 7.8

CVE-2025-41244

Broadcom VMware Aria Operations and VMware Tools — Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

CVSS 7.8

CVE-2025-24990

Microsoft Windows — Microsoft Windows Untrusted Pointer Dereference Vulnerability

CVSS 7.8

CVE-2025-59230

Microsoft Windows — Microsoft Windows Improper Access Control Vulnerability

CVSS 7.8

CVE-2025-8875

N-able N-Central — N-able N-Central Insecure Deserialization Vulnerability

CVSS 7.8

CVE-2025-30400

Microsoft Windows — Microsoft Windows DWM Core Library Use-After-Free Vulnerability

CVSS 7.8

CVE-2025-32701

Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

CVSS 7.8

CVE-2025-32706

Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

CVSS 7.8

CVE-2025-32709

Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

CVSS 7.8

CVE-2025-29824

Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

CVSS 7.8

CVE-2025-24985

Microsoft Windows — Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

CVSS 7.8

CVE-2025-24993

Microsoft Windows — Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

CVSS 7.8

CVE-2025-21418

Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

CVSS 7.8

CVE-2025-21333

Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability

CVSS 7.8

CVE-2025-21334

Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

CVSS 7.8

CVE-2025-21335

Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

CVSS 7.8

CVE-2025-20352

Cisco IOS and IOS XE — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

CVSS 7.7

CVE-2025-15556

Notepad++ Notepad++ — Notepad++ Download of Code Without Integrity Check Vulnerability

CVSS 7.5

CVE-2025-34026

Versa Concerto — Versa Concerto Improper Authentication Vulnerability

CVSS 7.5

CVE-2025-54313

Prettier eslint-config-prettier — Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

CVSS 7.5

CVE-2025-14847

MongoDB MongoDB and MongoDB Server — MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability

CVSS 7.5

CVE-2025-11371

Gladinet CentreStack and Triofox — Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability

CVSS 7.5

CVE-2025-61884

Oracle E-Business Suite — Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability

CVSS 7.5

CVE-2025-5777

Citrix NetScaler ADC and Gateway — Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability

CVSS 7.5

CVE-2025-27038

Qualcomm Multiple Chipsets — Qualcomm Multiple Chipsets Use-After-Free Vulnerability

CVSS 7.5

CVE-2025-30397

Microsoft Windows — Microsoft Windows Scripting Engine Type Confusion Vulnerability

CVSS 7.5

CVE-2025-38352

Linux Kernel — Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability

CVSS 7.4

CVE-2025-29635

D-Link DIR-823X (EoL) — Root RCE via Command Injection in set_prohibiting

CVSS 7.2

CVE-2025-2749

Kentico Xperience — Authenticated Path Traversal in Staging Sync Server Leading to Remote Code Execution

CVSS 7.2

CVE-2025-68461

Roundcube Webmail — RoundCube Webmail Cross-site Scripting Vulnerability

CVSS 7.2

CVE-2025-64328

Sangoma FreePBX — Sangoma FreePBX OS Command Injection Vulnerability

CVSS 7.2

CVE-2025-66644

Array Networks ArrayOS AG — Array Networks ArrayOS AG OS Command Injection Vulnerability

CVSS 7.2

CVE-2025-58034

Fortinet FortiWeb — Fortinet FortiWeb OS Command Injection Vulnerability

CVSS 7.2

CVE-2025-9377

TP-Link Multiple Routers — TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability

CVSS 7.2

CVE-2025-27920

Srimax Output Messenger — Srimax Output Messenger Directory Traversal Vulnerability

CVSS 7.2

CVE-2025-4428

Ivanti EPMM — Remote Code Execution via Spring EL Injection in Feature Usage API, Chained with Auth Bypass for Pre-Auth RCE

CVSS 7.2

CVE-2025-22226

VMware ESXi, Workstation, and Fusion — VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

CVSS 7.1

CVE-2025-21391

Microsoft Windows — Microsoft Windows Storage Link Following Vulnerability

CVSS 7.1

CVE-2025-62215

Microsoft Windows — Microsoft Windows Race Condition Vulnerability

CVSS 7

CVE-2025-24983

Microsoft Windows — Microsoft Windows Win32k Use-After-Free Vulnerability

CVSS 7

CVE-2025-26633

Microsoft Windows — Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

CVSS 7

CVE-2025-0411

7-Zip 7-Zip — 7-Zip Mark of the Web Bypass Vulnerability

CVSS 7

CVE-2025-1976

Broadcom Brocade Fabric OS — Broadcom Brocade Fabric OS Code Injection Vulnerability

CVSS 6.7

CVE-2025-40602

SonicWall SMA1000 appliance — SonicWall SMA1000 Missing Authorization Vulnerability

CVSS 6.6

CVE-2025-20362

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

CVSS 6.5

CVE-2025-49706

Microsoft SharePoint — Microsoft SharePoint Improper Authentication Vulnerability

CVSS 6.5

CVE-2025-24054

Microsoft Windows — Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

CVSS 6.5

CVE-2025-0111

Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS File Read Vulnerability

CVSS 6.5

CVE-2025-48700

Zimbra ZCS — Stored XSS in Classic UI via Crafted Email HTML with @import Directives

CVSS 6.1

CVE-2025-66376

Synacor Zimbra Collaboration Suite (ZCS) — Stored Cross-Site Scripting via CSS @import in Classic UI

CVSS 6.1

CVE-2025-59689

Libraesva Email Security Gateway — Libraesva Email Security Gateway Command Injection Vulnerability

CVSS 6.1

CVE-2025-24200

Apple iOS and iPadOS — Apple iOS and iPadOS Incorrect Authorization Vulnerability

CVSS 6.1

CVE-2025-25181

Advantive VeraCore — Advantive VeraCore SQL Injection Vulnerability

CVSS 5.8

CVE-2025-43520

Apple Multiple Products — Apple Multiple Products Classic Buffer Overflow Vulnerability

CVSS 5.5

CVE-2025-48633

Android Framework — Android Framework Information Disclosure Vulnerability

CVSS 5.5

CVE-2025-24991

Microsoft Windows — Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

CVSS 5.5

CVE-2025-27915

Zimbra ZCS — Stored XSS via ICS Calendar ontoggle Event, Zero-Day Exploited Against Brazilian Military

CVSS 5.4

CVE-2025-55177

Meta Platforms WhatsApp — Meta Platforms WhatsApp Incorrect Authorization Vulnerability

CVSS 5.4

CVE-2025-31125

Vite Vitejs — Vite Vitejs Improper Access Control Vulnerability

CVSS 5.3

CVE-2025-48927

TeleMessage TM SGNL — TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability

CVSS 5.3

CVE-2025-35939

Craft CMS Craft CMS — Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

CVSS 5.3

CVE-2025-4427

Ivanti EPMM — Authentication Bypass via Missing Spring Security Intercept Rules, Enabling Unauthenticated RCE Chain

CVSS 5.3

CVE-2025-47827

IGEL IGEL OS — IGEL OS Use of a Key Past its Expiration Date Vulnerability

CVSS 4.6

CVE-2025-24984

Microsoft Windows — Microsoft Windows NTFS Information Disclosure Vulnerability

CVSS 4.6

CVE-2025-21590

Juniper Junos OS — Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

CVSS 4.4

CVE-2025-47813

Wing FTP Server — Information Disclosure via Overlong UID Cookie in loginok.html

CVSS 4.3

CVE-2025-43200

Apple Multiple Products — Apple Multiple Products Unspecified Vulnerability

CVSS 4.2

CVE-2025-48928

TeleMessage TM SGNL — TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability

CVSS 4

CVE-2025-47729

TeleMessage TM SGNL — TeleMessage TM SGNL Hidden Functionality Vulnerability

CVSS 1.9