Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 10.0 critical | CVE-2025-47812 KEV | wftpserver Wing FTP Server In Wing FTP Server before 7.4.4. the user and admin web interfaces mishandle '\0' bytes, ultimately allowing injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). This is thus a remote code execution vulnerability that guarantees a total server compromise. This is also exploitable via anonymous FTP accounts. | 93% | 10 Jul 2025 |
| 8.0 high | CVE-2025-48384 KEV | git Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return and line feed (CRLF). When writing a config entry, values with a trailing CR are not quoted, causing the CR to be lost when the config is later read. When initializing a submodule, if the submodule path contains a trailing CR, the altered path is read resulting in the submodule being checked out to an incorrect location. If a symlink exists that points the altered path to the submodule hooks directory, and the submodule contains an executable post-checkout hook, the script may be unintentionally executed after checkout. This vulnerability is fixed in v2.43.7, v2.44.4, v2.45.4, v2.46.4, v2.47.3, v2.48.2, v2.49.1, and v2.50.1. | 4.2% | 8 Jul 2025 |
| 6.5 medium | CVE-2025-49706 KEV | Microsoft SharePoint Enterprise Server 2016 Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 99% | 8 Jul 2025 |
| 8.8 high | CVE-2025-49704 KEV | Microsoft SharePoint Enterprise Server 2016 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | >99% | 8 Jul 2025 |
| 8.1 high | CVE-2025-6554 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | 14% | 30 Jun 2025 |
| 7.8 high | CVE-2025-32463 KEV | Sudo project Sudo Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option. | 55% | 30 Jun 2025 |
| 10.0 critical | CVE-2025-20281 KEV | Cisco Identity Services Engine Software A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by submitting a crafted API request. A successful exploit could allow the attacker to obtain root privileges on an affected device. | 98% | 25 Jun 2025 |
| 9.2 critical | CVE-2025-6543 KEV | NetScaler ADC Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | 11% | 25 Jun 2025 |
| 10.0 critical | CVE-2025-32975 KEV | quest kace systems management appliance Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials. The vulnerability exists in the SSO authentication handling mechanism and can lead to complete administrative takeover. | 2.5% | 24 Jun 2025 |
| 6.1 medium | CVE-2025-48700 KEV | synacor zimbra collaboration suite An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to sensitive information. This issue arises from insufficient sanitization of HTML content, specifically involving crafted tag structures and attribute values that include an @import directive and other script injection vectors. The vulnerability is triggered when a user views a crafted e-mail message in the Classic UI, requiring no additional user interaction. | 1.7% | 23 Jun 2025 |
| 7.8 high | CVE-2025-6218 KEV | RARLAB WinRAR RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198. | 90% | 21 Jun 2025 |
| 9.3 critical | CVE-2025-5777 KEV | NetScaler ADC Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | >99% | 17 Jun 2025 |
| 4.2 medium | CVE-2025-43200 KEV | Apple iOS and iPadOS This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals. | 1.2% | 16 Jun 2025 |
| 8.8 high | CVE-2025-33073 KEV | Microsoft Windows 10 Version 1507 Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network. | 83% | 10 Jun 2025 |
| 8.8 high | CVE-2025-33053 KEV | Microsoft Windows 10 Version 1507 External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | 87% | 10 Jun 2025 |
| 4.6 medium | CVE-2025-47827 KEV | igel os In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. | 4.9% | 5 Jun 2025 |
| 8.6 high | CVE-2025-21479 KEV | Qualcomm, Inc. Snapdragon Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | 0.84% | 3 Jun 2025 |
| 7.5 high | CVE-2025-27038 KEV | Qualcomm, Inc. Snapdragon Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | 1.0% | 3 Jun 2025 |
| 8.6 high | CVE-2025-21480 KEV | Qualcomm, Inc. Snapdragon Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | 0.46% | 3 Jun 2025 |
| 8.8 high | CVE-2025-5419 KEV | Google Chrome Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 7.8% | 3 Jun 2025 |