KEV 2025
182 CISA Known Exploited Vulnerabilities from 2025
Critical 72
April 2026
March 2026
Craft CMS — Pre-Auth PHP Object Injection Enabling Remote Code Execution (CVSS 10)
CVSS 10n8n — Expression Injection Sandbox Escape Enabling Unauthenticated RCE (MuddyWater Exploited)
CVSS 9.9F5 BIG-IP APM — Remote Code Execution via Malicious Traffic to Access Policy Virtual Server
CVSS 9.8Laravel Livewire v3 — Hydration Deserialization Enabling Pre-Auth RCE (MuddyWater Exploited)
CVSS 9.8SolarWinds Web Help Desk — AjaxProxy Deserialization Bypass RCE (3rd Iteration; Warlock Ransomware Chain)
CVSS 9.8February 2026
Roundcube Webmail — Authenticated PHP Object Deserialization via _from Parameter; 85,000 Exposed Instances
CVSS 9.9React Native CLI Metro Server — Pre-Auth OS Command Injection via /open-url Endpoint (Metro4Shell; ~2.5M Weekly Downloads)
CVSS 9.8SolarWinds Web Help Desk — Pre-Auth Java Deserialization RCE via jabsorb Bypass (3-Day CISA Deadline)
CVSS 9.8January 2026
SmarterMail — Pre-Auth Arbitrary File Upload to RCE (CVSS 10; Handala-Linked Exploitation)
CVSS 10HPE OneView — Unauthenticated REST API Code Injection RCE (CVSS 10; RondoDox Botnet — 40,000 Attacks)
CVSS 10December 2025
Cisco Secure Email Gateway / AsyncOS — Pre-Auth Spam Quarantine RCE; UNC-9686 (China) Deploys AquaShell
CVSS 10React Server Components — React2Shell: Pre-Auth Deserialization RCE in Flight Protocol (CVSS 10, Ransomware)
CVSS 10WatchGuard Firebox iked — Pre-Auth OOB Write via IKEv2 CERT Payload; 117,000 Exposed Devices
CVSS 9.8ASUS Live Update — Operation ShadowHammer Supply Chain Backdoor (APT41 / Brass Typhoon)
CVSS 9.8Fortinet FortiOS / FortiProxy / FortiWeb — FortiCloud SAML SSO Authentication Bypass; Exploited 3 Days Post-Disclosure
CVSS 9.8Gladinet CentreStack / Triofox — Hardcoded AES Keys Enable LFI → web.config Exfiltration → ViewState RCE (Clop-Linked)
CVSS 9.8November 2025
Oracle Identity Manager — Pre-Auth Groovy RCE via URI Suffix Bypass; Zero-Day Since August 2025
CVSS 9.8Fortinet FortiWeb — Pre-Auth Path Traversal to Admin RCE; Mass Exploitation Since July 2025
CVSS 9.8WatchGuard Firebox — iked Pre-Auth OOB Write via IKEv2 IDi Payload; 54k+ Unpatched Appliances at KEV Listing
CVSS 9.8Gladinet Triofox — Host Header Spoofing Bypasses Setup Auth → Admin Account Creation → SYSTEM RCE via AV Engine (UNC6485)
CVSS 9.1CWP Control Web Panel — Pre-Auth OS Command Injection in File Manager (220,000+ Exposed Servers)
CVSS 9October 2025
Adobe AEM Forms (JEE) — Pre-Auth OGNL RCE via Struts devMode Debug Endpoint (CVSS 10)
CVSS 10XWiki Platform — Pre-Auth Groovy Eval Injection via SolrSearch Enabling RCE on Any XWiki Instance
CVSS 9.8Microsoft WSUS — Pre-Auth .NET Deserialization RCE; Mass Exploitation Day Before Patch (UNC6512)
CVSS 9.8LANSCOPE Endpoint Manager — Unauthenticated Remote Code Execution via Spoofed Communication Channel, Exploited by Chinese APT Bronze Butler
CVSS 9.8Kentico Xperience CMS — Staging Service PasswordDigest Auth Bypass; Chains for Pre-Auth RCE (WatchTowr)
CVSS 9.8Kentico Xperience CMS — WSE 3.0 No-Password Auth Bypass; Second Bypass Path in Staging Service RCE Chain
CVSS 9.8Oracle E-Business Suite — Pre-Auth RCE in BI Publisher / Concurrent Processing; Cl0p Zero-Day Campaign
CVSS 9.8Dassault Systèmes DELMIA Apriso — Unauthenticated SOAP Account Creation; ICS/MES Exploitation Chain with CVE-2025-6204
CVSS 9.1Adobe Commerce / Magento — SessionReaper: Pre-Auth REST API File Upload to Webshell RCE (250+ Stores Hit Overnight)
CVSS 9.1September 2025
Fortra GoAnywhere MFT — Pre-Auth 3-Bug Chain (Auth Bypass + Deserialization RCE); Storm-1175/Medusa Ransomware
CVSS 10Cisco ASA/FTD VPN — Buffer Overflow RCE in VPN Web Server; UAT4356 (ArcaneDoor); Emergency Directive ED-25-03 (1-Day Deadline)
CVSS 9.9Google Chrome — V8 TurboFan JIT Type Confusion; Pre-Patch Zero-Day Exploited in the Wild (Google TAG)
CVSS 9.8Sudo — sudo --chroot NSS Library Loading Enables Any Local User to Execute Arbitrary Commands as Root
CVSS 9.3Dassault Systèmes DELMIA Apriso — FlexNetOperationsService .NET Deserialization RCE; Espionage Trojan Deployment
CVSS 9Sitecore XM/XP/XC — ASP.NET Machine Key ViewState Deserialization RCE; WEEPSTEEL Malware (Mandiant)
CVSS 9August 2025
Apple ImageIO — Zero-Click Out-of-Bounds Write in Image Parsing; Chained in WhatsApp Spyware Attack
CVSS 10Sangoma FreePBX EndPoint Manager — Pre-Auth SQL Injection Enabling Account Takeover and RCE
CVSS 9.8Citrix NetScaler ADC/Gateway — Pre-Auth Zero-Day Memory Overflow; Emergency 48-Hour CISA Deadline; 14k+ Exposed
CVSS 9.8Trend Micro Apex One — Pre-Auth OS Command Injection in Management Console (Zero-Day)
CVSS 9.4July 2025
Cisco ISE — Pre-Auth API Injection Enabling Root RCE (CVSS 10; Companion to CVE-2025-20337)
CVSS 10Cisco ISE — Second Pre-Auth API Injection Enabling Root RCE (CVSS 10; Same Advisory as CVE-2025-20281)
CVSS 10Wing FTP Server — Null Byte Injection Enabling Lua Code Execution as SYSTEM/root (CVSS 10)
CVSS 10Microsoft SharePoint — ToolShell: Pre-Auth Deserialization RCE (Chinese APTs Linen Typhoon, Violet Typhoon; Ransomware)
CVSS 9.8Fortinet FortiWeb — Pre-Auth SQL Injection to RCE via Fabric Connector Bearer Token (Exploited 3 Days Post-PoC)
CVSS 9.8SysAid On-Prem — Pre-Auth XXE via /mdm/checkin; Part of SysOwned Chain Enabling Credential Theft and SYSTEM RCE
CVSS 9.3SysAid On-Prem — Pre-Auth XXE via /mdm/serverurl; Companion to CVE-2025-2775 in SysOwned SYSTEM RCE Chain
CVSS 9.3CrushFTP — AS2 Validation Bypass Enabling Pre-Auth Admin Takeover (Zero-Day, Exploit Sold on Forums)
CVSS 9June 2025
Erlang/OTP — Pre-Authentication Remote Code Execution via SSH Channel Request
CVSS 10Wazuh Server — Authenticated Python Pickle Deserialization RCE via REST API (CVSS 9.9)
CVSS 9.9Citrix NetScaler ADC/Gateway — Pre-Auth Buffer Overflow (Gateway/AAA Mode); Active Exploitation; 2,100+ Unpatched
CVSS 9.8May 2025
Commvault Command Center — Pre-Auth Path Traversal to Webshell RCE (CVSS 10; watchTowr)
CVSS 10Samsung MagicINFO 9 Server — Unauthenticated Arbitrary File Write as SYSTEM; Patch Bypass of CVE-2024-7399; Mirai Botnet
CVSS 9.8Fortinet FortiVoice / FortiMail / FortiNDR / FortiRecorder / FortiCamera — Pre-Auth Stack Overflow RCE (Zero-Day)
CVSS 9.8Langflow — Unauthenticated Python Code Execution via /api/v1/validate/code; Cryptominer Campaigns
CVSS 9.8SAP NetWeaver Visual Composer — Deserialization RCE Chained with CVE-2025-31324; Earth Lamia (China-Nexus APT)
CVSS 9.1April 2025
SAP NetWeaver Visual Composer — Pre-Auth Webshell Upload via Metadata Uploader (CVSS 10; Earth Lamia, Ransomware)
CVSS 10Qualitia Active! Mail — Pre-Auth Stack Buffer Overflow RCE; Zero-Day Targeting Japanese Universities and Hosting Providers
CVSS 9.8Apple CoreAudio — Memory Corruption in Audio Stream Processing Enabling Code Execution (Chained with CVE-2025-31201; Google TAG)
CVSS 9.8Apple RPAC — Pointer Authentication Bypass Enabling Sandbox Escape (Chained with CVE-2025-31200; Google TAG)
CVSS 9.8CrushFTP — HTTP Authorization Header Spoofing Enabling Pre-Auth Account Takeover (Ransomware, Fog)
CVSS 9.8Apache Tomcat — Partial PUT Deserialization RCE via Session File Upload (File-Based Sessions + Partial PUT)
CVSS 9.8Gladinet CentreStack / Triofox — ASP.NET Hard-coded Machine Key Enables ViewState Deserialization RCE
CVSS 9Ivanti Connect Secure — Stack Buffer Overflow RCE Exploited by UNC5221 with SPAWN Malware (7-Day CISA Deadline)
CVSS 9March 2025
Apple WebKit — Out-of-Bounds Write Enabling Web Content Sandbox Escape (Zero-Day, March 2025)
CVSS 10Edimax IC-7100 IP Camera — Pre-Auth OS Command Injection; End-of-Life Device; Mirai Botnet Recruitment; No Patch Available
CVSS 9.8VMware ESXi / Workstation — TOCTOU Race Condition OOB Write Enabling Guest-to-Host VM Escape (VMSA-2025-0004)
CVSS 9.3February 2025
January 2025
Apple Core Media — Use-After-Free Enabling Local Privilege Escalation (Zero-Day, January 2025)
CVSS 10SonicWall SMA1000 — Pre-Auth Deserialization RCE in AMC/CMC Management Console (Ransomware, Zero-Day)
CVSS 9.8Ivanti Connect Secure — Pre-Auth Zero-Day Stack Overflow; UNC5221 Deploys SPAWN Malware; Emergency 7-Day CISA Deadline
CVSS 9High 83
June 2026
May 2026
April 2026
Windows Host Process for Tasks (taskhostw.exe) — Symbolic Link Abuse Leading to SYSTEM Privilege Escalation
CVSS 7.8D-Link DIR-823X (EoL) — Root RCE via Command Injection in set_prohibiting
CVSS 7.2Kentico Xperience — Authenticated Path Traversal in Staging Sync Server Leading to Remote Code Execution
CVSS 7.2March 2026
Apple iOS/Safari — WebKit/JavaScriptCore JIT Buffer Overflow; DarkSword Exploit Chain (UNC6748, PARS Defense, UNC6353)
CVSS 8.8Apple iOS/macOS/watchOS — DarkSword Chain Shared-Memory LPE; Targeted Spyware Deployment
CVSS 7.8February 2026
SolarWinds Web Help Desk — CSRF Bypass via /ajax/ URI Injection; Chains with CVE-2025-40551 for Unauthenticated RCE; 3-Day Emergency Deadline
CVSS 8.1Notepad++ WinGUp Updater — No Crypto Verification of Updates; Hosting Provider Compromise Enables Trojanized Installer Delivery
CVSS 7.5Roundcube Webmail — SVG animate Tag XSS Bypasses rcube_washtml Sanitizer; Persistent Zero-Click Session Theft
CVSS 7.2Sangoma FreePBX Endpoint Manager — Post-Auth OS Command Injection via SSH Test Function
CVSS 7.2January 2026
Zimbra ZCS — /h/rest Servlet Path Traversal File Inclusion; APT Target; Session Credential Exfiltration
CVSS 8.8Gogs Git Server — Symlink Path Traversal in PutContents API; Authenticated Repo User Can Read/Write Arbitrary Files; Wiz Research
CVSS 8.8Versa Concerto SD-WAN — Traefik Header Drop Bypasses Actuator Auth; Part of 3-CVE Chain for Unauthenticated RCE
CVSS 7.5npm eslint-config-prettier — Maintainer Account Compromise via Phishing; node-gyp.dll Malware on Windows; 30M+ Weekly Downloads
CVSS 7.5December 2025
Apple iOS/macOS — WebKit UAF Zero-Day; Mercenary Spyware Targeting; Apple's 9th Exploited Zero-Day of 2025
CVSS 8.8Google Chrome ANGLE — OOB Memory Access on macOS; Same-Day KEV Listing as Patch; Affects All Chromium-Based Browsers
CVSS 8.8OSGeo GeoServer — Pre-Auth XXE via WMS GetMap; Arbitrary File Read and SSRF; New Year's Day 2026 CISA Deadline
CVSS 8.2WinRAR Windows — Earlier Path Traversal (June 2025); KEV-Listed December 2025; Distinct from CVE-2025-8088; Fixed in 7.20
CVSS 7.8Windows Cloud Files Mini Filter Driver (cldflt.sys) — UAF Local Privilege Escalation; December 2025 Patch Tuesday Zero-Day
CVSS 7.8Android Framework — Background Activity Launch Restriction Bypass; Limited Targeted Exploitation; December 2025
CVSS 7.8MongoDB — Unauthenticated Heap Memory Leak via Zlib Inconsistent Length Fields; Pre-Auth Confidentiality Impact
CVSS 7.5Array Networks ArrayOS AG — Authenticated Command Injection via DesktopDirect; Webshell Deployment; JPCERT-Confirmed Active Exploitation
CVSS 7.2November 2025
Google Chrome V8 — Type Confusion Heap Corruption; November 2025 Zero-Day; Affects All Chromium-Based Browsers
CVSS 8.8Samsung Mobile — libimagecodec.quram.so OOB Write; Linked to Landfall Commercial Spyware (Unit 42); April 2025 SMR
CVSS 8.8Gladinet CentreStack/Triofox — Unauthenticated Local File Inclusion; Third Gladinet CVE of 2025; Systemic Access Control Deficit
CVSS 7.5Fortinet FortiWeb — Authenticated OS Command Injection; 7-Day CISA Deadline; 22k+ Exposed Appliances
CVSS 7.2Windows Kernel — Double-Free Race Condition; Local Privilege Escalation to SYSTEM; November 2025 Patch Tuesday Zero-Day
CVSS 7October 2025
Microsoft Windows — SMB Client Coercion Attack; Credential Relay / Privilege Escalation via Malicious Script
CVSS 8.8Samsung Mobile — libimagecodec.quram.so OOB Write; Reported by Meta/WhatsApp; Android 13–16; September 2025 SMR
CVSS 8.8Smartbedded Meteobridge — Unauthenticated Root Command Injection in Weather Station Bridge; IoT Botnet Recruitment Risk
CVSS 8.8Dassault Systèmes DELMIA Apriso — Authenticated File Upload Code Injection; Step 2 of CVE-2025-6205 → RCE Chain; ICS/MES Target
CVSS 8VMware Aria Operations / VMware Tools — SDMP get_versions.sh Unsafe Path; UNC5174 (China) Zero-Day for ~1 Year Before Patch
CVSS 7.8Windows Agere Modem Driver (ltmdm64.sys) — 2006 Legacy Driver IOCTL Pointer Dereference; Microsoft Removes Driver Entirely
CVSS 7.8Windows Remote Access Connection Manager — Local Privilege Escalation to SYSTEM; October 2025 Patch Tuesday Zero-Day
CVSS 7.8Oracle EBS Configurator — SSRF → XSL SSTI RCE Chain; Cl0p/FIN11 Mass Extortion Campaign; SAGE Malware Framework
CVSS 7.5September 2025
Android Runtime — ART UAF Chrome Sandbox Escape; Paired with CVE-2025-38352 for Full Kernel LPE; Limited Targeted Exploitation
CVSS 8.8Cisco IOS/IOS XE — SNMP Stack Overflow; DoS with Low Priv, RCE with Admin Creds; Active Exploitation Confirmed
CVSS 7.7Linux Kernel — POSIX CPU Timer TOCTOU Race; Android September 2025 Zero-Day; Kernel Memory Corruption
CVSS 7.4TP-Link Archer C7 / WR841N — Authenticated Command Injection via Parental Control; EOL Hardware; CISA Recommends Discontinue Use
CVSS 7.2August 2025
N-able N-Central RMM — Authenticated Command Injection; 7-Day Emergency CISA Deadline; MSP Supply-Chain Risk
CVSS 8.8WinRAR Windows — Path Traversal via ...// Archive Entry Names; Amaranth Dragon (APT41-linked) and RomCom Exploitation; Fixed in 7.13
CVSS 8.8Git — Pre-Auth RCE via Carriage Return in Submodule Path (Linux/macOS)
CVSS 8N-able N-Central RMM — Java Deserialization RCE; Paired with CVE-2025-8876 Command Injection; 7-Day Emergency Deadline
CVSS 7.8July 2025
Microsoft SharePoint Server — Authenticated Code Injection; 1-Day CISA Deadline; Chains with CVE-2025-49706; Patch Bypassed by CVE-2025-53770
CVSS 8.8Google Chrome ANGLE/GPU — Sandbox Escape via GPU Process; Affects All Chromium-Based Browsers; July 2025 Zero-Day
CVSS 8.8Google Chrome V8 — Type Confusion Arbitrary Read/Write; Fourth Chrome Zero-Day of 2025; June 2025
CVSS 8.1Citrix NetScaler ADC/Gateway — Pre-Auth OOB Read Memory Disclosure; 1-Day CISA Emergency Deadline; Ransomware Exploitation
CVSS 7.5June 2025
Microsoft Windows — .url File WorkingDirectory WebDAV Code Execution; June 2025 Patch Tuesday Zero-Day
CVSS 8.8Google Chrome V8 — OOB Read/Write Heap Corruption; Third Chrome Zero-Day of 2025; June 2025
CVSS 8.8Qualcomm Adreno GPU — Second Unauthorized GPU Micronode Command Execution Vulnerability; June 2025 Bulletin (Companion to CVE-2025-21480)
CVSS 8.6Qualcomm Adreno GPU — Unauthorized GPU Micronode Command Execution Enabling Memory Corruption; June 2025 Bulletin
CVSS 8.6ConnectWise ScreenConnect — ViewState Code Injection via Exposed Machine Key; RCE on Server; April 2025 Security Patch
CVSS 8.1Qualcomm Adreno GPU — UAF via Chrome Renderer; Remote Exploitation via Malicious Web Content; June 2025 Bulletin
CVSS 7.5May 2025
FreeType — TrueType GX / Variable Font OOB Write; Android/Linux/macOS Affected; Meta Reports Active Exploitation
CVSS 8.1Windows Desktop Window Manager — DwmCore.dll UAF Local Privilege Escalation; May 2025 Patch Tuesday Zero-Day
CVSS 7.8Windows CLFS Driver — UAF Local Privilege Escalation; May 2025 Patch Tuesday Zero-Day (One of Three Simultaneous)
CVSS 7.8Windows CLFS Driver — Heap Overflow Local Privilege Escalation; May 2025 Patch Tuesday Zero-Day
CVSS 7.8Microsoft Windows — AFD.sys Use-After-Free; Local Privilege Escalation to Administrator; May 2025 Patch Tuesday Zero-Day
CVSS 7.8Windows Scripting Engine — Type Confusion RCE via Crafted URL; May 2025 Patch Tuesday Zero-Day
CVSS 7.5Srimax Output Messenger — Path Traversal to Startup Folder Persistence; Marbled Dust Targets Kurdish Military in Iraq
CVSS 7.2Ivanti EPMM — Remote Code Execution via Spring EL Injection in Feature Usage API, Chained with Auth Bypass for Pre-Auth RCE
CVSS 7.2April 2025
Commvault Web Server — Authenticated Webshell Creation via Unspecified Flaw; Ransomware-Group Exploitation
CVSS 8.8Windows CLFS Driver — Zero-Day UAF Used by Storm-2460 to Deploy RansomEXX; April 2025 Patch Tuesday
CVSS 7.8March 2025
reviewdog/action-setup — CI/CD Supply Chain Cascade: Upstream Compromise Enables Downstream tj-actions Attack
CVSS 8.6tj-actions/changed-files — CI/CD Supply Chain Attack Dumps Secrets to Workflow Logs; 23,000+ Repos Affected; Coinbase Initial Target
CVSS 8.6Google Chrome Mojo (Windows) — IPC Handle Logic Error Enables Sandbox Escape; Operation ForumTroll Russian APT; March 2025 Zero-Day
CVSS 8.3VMware ESXi — VMX Process Arbitrary Kernel Write → Host Escape; Part of VMSA-2025-0004 Guest Escape Chain; Ransomware Exploitation
CVSS 8.2Fortinet FortiOS/FortiProxy — Auth Bypass via CSF Proxy Requests → Super-Admin; Ransomware Active Exploitation
CVSS 8.1Windows Fast FAT Driver (fastfat.sys) — Integer Overflow via Malicious Disk Image; March 2025 Patch Tuesday Zero-Day
CVSS 7.8Windows NTFS Driver — Heap Overflow via Malicious .vhd File; March 2025 Patch Tuesday Zero-Day
CVSS 7.8VMware ESXi/Workstation/Fusion — HGFS OOB Read Leaks vmx Process Memory; Part of VMSA-2025-0004 Guest Escape Chain
CVSS 7.1Windows Win32k Kernel Subsystem — UAF Local Privilege Escalation; March 2025 Patch Tuesday Zero-Day
CVSS 7Windows MMC — MSC EvilTwin .msc File Security Bypass; EncryptHub/Larva-208 Zero-Day; RansomHub Delivery
CVSS 7February 2025
Trimble Cityworks — Authenticated .NET Deserialization RCE Against IIS Web Server; Targets Government and Utility Infrastructure
CVSS 8.8Microsoft Power Pages — Unauthenticated Privilege Escalation via Registration Bypass; Microsoft Discloses Active Exploitation of Customer Portals
CVSS 8.2Craft CMS — Database Backup Path Code Injection; RCE When Security Key is Known to Attacker
CVSS 8Windows AFD (afd.sys) — Heap Overflow Local Privilege Escalation to SYSTEM; February 2025 Patch Tuesday Zero-Day
CVSS 7.8Windows Storage — Symlink Following Enables Arbitrary File Deletion; February 2025 Patch Tuesday Zero-Day
CVSS 7.17-Zip — MotW Not Propagated to Extracted Files; Windows SmartScreen Bypass; Russian SmokeLoader Phishing Campaigns
CVSS 7January 2025
Windows Hyper-V NT Kernel VSP — Heap Overflow Guest-to-Host LPE; January 2025 Patch Tuesday (One of Three Simultaneous Hyper-V Zero-Days)
CVSS 7.8Windows Hyper-V NT Kernel VSP — UAF Guest-to-Host LPE; January 2025 Patch Tuesday (One of Three Simultaneous Hyper-V Zero-Days)
CVSS 7.8Windows Hyper-V NT Kernel VSP — UAF Guest-to-Host LPE; January 2025 Patch Tuesday (Third of Three Simultaneous Hyper-V Zero-Days)
CVSS 7.8Medium 26
April 2026
March 2026
Synacor Zimbra Collaboration Suite (ZCS) — Stored Cross-Site Scripting via CSS @import in Classic UI
CVSS 6.1Apple iOS, iPadOS, macOS, watchOS, tvOS, visionOS — Kernel Memory Write via Buffer Overflow
CVSS 5.5Wing FTP Server — Information Disclosure via Overlong UID Cookie in loginok.html
CVSS 4.3January 2026
December 2025
SonicWall SMA1000 — Privilege Escalation to Root in Appliance Management Console
CVSS 6.6Android Framework — Sandbox-Escaping Information Disclosure, Exploited in Targeted Campaigns
CVSS 5.5October 2025
Zimbra ZCS — Stored XSS via ICS Calendar ontoggle Event, Zero-Day Exploited Against Brazilian Military
CVSS 5.4IGEL OS — Secure Boot Bypass via Expired Signing Key in igel-flash-driver Module
CVSS 4.6September 2025
Cisco ASA/FTD — Unauthenticated Authorization Bypass in VPN Web Server, Chained with Critical RCE
CVSS 6.5Libraesva ESG — Nation-State Exploited Command Injection via Compressed Email Attachment
CVSS 6.1Meta WhatsApp for iOS/macOS — Zero-Click Exploit Chain via Linked Device Sync Spoofing
CVSS 5.4July 2025
Microsoft SharePoint Server — Authentication Bypass Enabling Spoofing, Chained via CVE-2025-49704; Patch Bypass in CVE-2025-53771
CVSS 6.5TeleMessage TM SGNL — Unauthenticated Spring Boot Actuator /heapdump Endpoint Exposed
CVSS 5.3TeleMessage TM SGNL — Heap Dump Contains Cleartext Passwords Transmitted over HTTP
CVSS 4June 2025
Craft CMS — Pre-Auth PHP Code Injection via Immutable Parameter Manipulation, Chains to RCE
CVSS 5.3Apple iOS/iPadOS/macOS/watchOS/visionOS — Memory Corruption via Malicious iCloud-Shared Photo or Video
CVSS 4.2May 2025
April 2025
Broadcom Brocade Fabric OS — Local Admin to Full Root via Code Injection on SAN Switches
CVSS 6.7Microsoft Windows — NTLM Hash Capture via Crafted .library-ms File
CVSS 6.5March 2025
Advantive VeraCore — Unauthenticated SQL Injection in timeoutWarning.asp
CVSS 5.8Microsoft Windows NTFS — Out-of-Bounds Read Discloses Memory Contents via Crafted Volume
CVSS 5.5Microsoft Windows NTFS — Physical-Access Attack Writes Heap Memory to Log Files
CVSS 4.6Juniper Junos OS — Shell-Access Privilege Boundary Bypass Enables Arbitrary Code Execution
CVSS 4.4