Exploited vulnerabilities
CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.
| Score | CVE | Affected | EPSS | Published |
|---|---|---|---|---|
| 9.0 critical | CVE-2025-5086 KEV | Dassault Systèmes DELMIA Apriso A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution. | 97% | 2 Jun 2025 |
| 8.8 high | CVE-2025-49113 KEV | Roundcube Webmail Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. | 99% | 2 Jun 2025 |
| 4.0 medium | CVE-2025-48928 KEV | TeleMessage service The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025. | 0.55% | 28 May 2025 |
| 5.3 medium | CVE-2025-48927 KEV | TeleMessage service The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025. | 11% | 28 May 2025 |
| 9.2 critical | CVE-2025-34026 KEV | Versa Concerto The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace logs.This issue is known to affect Concerto from 12.1.2 through 12.2.0. Additional versions may be vulnerable. | 82% | 21 May 2025 |
| 8.7 high | CVE-2025-4008 KEV | Smartbedded MeteoBridge The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command injection. Remote unauthenticated attackers can gain arbitrary command execution with elevated privileges ( root ) on affected devices. | 94% | 21 May 2025 |
| 7.8 high | CVE-2025-32709 KEV | Microsoft Windows 10 Version 1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 2.2% | 13 May 2025 |
| 7.8 high | CVE-2025-32706 KEV | Microsoft Windows 10 Version 1507 Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.3% | 13 May 2025 |
| 7.8 high | CVE-2025-32701 KEV | Microsoft Windows 10 Version 1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 1.4% | 13 May 2025 |
| 7.8 high | CVE-2025-30400 KEV | Microsoft Windows 10 Version 1809 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | 1.9% | 13 May 2025 |
| 7.5 high | CVE-2025-30397 KEV | Microsoft Windows 10 Version 1507 Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | 27% | 13 May 2025 |
| 8.8 high | CVE-2025-4428 KEV | Ivanti Endpoint Manager Mobile Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests. | 87% | 13 May 2025 |
| 7.5 high | CVE-2025-4427 KEV | Ivanti Endpoint Manager Mobile An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API. | >99% | 13 May 2025 |
| 9.8 critical | CVE-2025-32756 KEV | Fortinet FortiNDR A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie. | 30% | 13 May 2025 |
| 9.8 critical | CVE-2025-4632 KEV | Samsung Electronics MagicINFO 9 Server Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority. | 24% | 13 May 2025 |
| 9.1 critical | CVE-2025-42999 KEV | SAP_SE SAP NetWeaver (Visual Composer development server) SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system. | 14% | 13 May 2025 |
| 4.9 medium | CVE-2025-47729 KEV | TeleMessage archiving backend The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025. | 0.45% | 8 May 2025 |
| 6.9 medium | CVE-2025-35939 KEV | Craft CMS Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can introduce arbitrary values, such as PHP code, to a known local file location on the server. Craft CMS versions 5.7.5 and 4.15.3 have been released to address this issue. | 1.3% | 7 May 2025 |
| 9.8 critical | CVE-2025-2776 KEV | SysAid On-Prem SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. | 65% | 7 May 2025 |
| 7.5 high | CVE-2025-2775 KEV | SysAid On-Prem SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. | 43% | 7 May 2025 |