Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 8.1 high | CVE-2025-6554 KEV | Google Chrome Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) | 14% | 2 Jul 2025 |
| 4.0 medium | CVE-2025-48928 KEV | TeleMessage service The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025. | 0.55% | 1 Jul 2025 |
| 5.3 medium | CVE-2025-48927 KEV | TeleMessage service The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025. | 11% | 1 Jul 2025 |
| 9.2 critical | CVE-2025-6543 KEV | NetScaler ADC Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | 11% | 30 Jun 2025 |
| 10.0 critical | CVE-2024-54085 KEV | AMI MegaRAC-SPx AMI’s SPx contains a vulnerability in the BMC where an Attacker may bypass authentication remotely through the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability. | 61% | 25 Jun 2025 |
| 9.8 critical | CVE-2024-0769 KEV | D-Link DIR-859 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-251666 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced. | 83% | 25 Jun 2025 |
| 6.5 medium | CVE-2019-6693 KEV | Fortinet FortiGate Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data includes users' passwords (except the administrator's password), private keys' passphrases and High Availability password (when set). | 5.8% | 25 Jun 2025 |
| 7.8 high | CVE-2023-0386 KEV | Kernel A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system. | 7.9% | 17 Jun 2025 |
| 4.2 medium | CVE-2025-43200 KEV | Apple iOS and iPadOS This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals. | 1.2% | 16 Jun 2025 |
| 8.8 high | CVE-2023-33538 KEV | tp-link tl-wr940n firmware TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . | 42% | 16 Jun 2025 |
| 8.8 high | CVE-2025-33053 KEV | Microsoft Windows 10 Version 1507 External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network. | 87% | 10 Jun 2025 |
| 9.9 critical | CVE-2025-24016 KEV | wazuh Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 and prior to version 4.9.1, an unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. DistributedAPI parameters are a serialized as JSON and deserialized using `as_wazuh_object` (in `framework/wazuh/core/cluster/common.py`). If an attacker manages to inject an unsanitized dictionary in DAPI request/response, they can forge an unhandled exception (`__unhandled_exc__`) to evaluate arbitrary python code. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster) or, in certain configurations, even by a compromised agent. Version 4.9.1 contains a fix. | 94% | 10 Jun 2025 |
| 10.0 critical | CVE-2025-32433 KEV | erlang otp Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules. | 99% | 9 Jun 2025 |
| 9.3 critical | CVE-2024-42009 KEV | roundcube webmail A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php. | 83% | 9 Jun 2025 |
| 8.8 high | CVE-2025-5419 KEV | Google Chrome Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 7.8% | 5 Jun 2025 |
| 8.6 high | CVE-2025-21479 KEV | Qualcomm, Inc. Snapdragon Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | 0.84% | 3 Jun 2025 |
| 7.5 high | CVE-2025-27038 KEV | Qualcomm, Inc. Snapdragon Memory corruption while rendering graphics using Adreno GPU drivers in Chrome. | 1.0% | 3 Jun 2025 |
| 8.6 high | CVE-2025-21480 KEV | Qualcomm, Inc. Snapdragon Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands. | 0.46% | 3 Jun 2025 |
| 6.9 medium | CVE-2025-35939 KEV | Craft CMS Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]' is provided to the client in a 'Set-Cookie' response header. Craft CMS stores the return URL requested by the client without sanitizing parameters. Consequently, an unauthenticated client can introduce arbitrary values, such as PHP code, to a known local file location on the server. Craft CMS versions 5.7.5 and 4.15.3 have been released to address this issue. | 1.3% | 2 Jun 2025 |
| 7.2 high | CVE-2025-3935 KEV | ConnectWise ScreenConnect ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys. It is important to note that to obtain these machine keys, privileged system level access must be obtained. If these machine keys are compromised, attackers could create and send a malicious ViewState to the website, potentially leading to remote code execution on the server. The risk does not originate from a vulnerability introduced by ScreenConnect, but from platform level behavior. This had no direct impact to ScreenConnect Client. ScreenConnect 2025.4 patch disables ViewState and removes any dependency on it. | 3.5% | 2 Jun 2025 |