Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 9.3 critical | CVE-2024-56145 KEV | craftcms cms Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue. | 97% | 2 Jun 2025 |
| 8.8 high | CVE-2023-39780 KEV | ASUS RT-AX55 On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the similar "token-refresh module" issue, see CVE-2023-41346; for the similar "check token module" issue, see CVE-2023-41347; and for the similar "code-authentication module" issue, see CVE-2023-41348. | 40% | 2 Jun 2025 |
| 9.8 critical | CVE-2021-32030 KEV | asus lyra mini firmware The administrator application on ASUS GT-AC2900 devices before 3.0.0.4.386.42643 and Lyra Mini before 3.0.0.4_384_46630 allows authentication bypass when processing remote input from an unauthenticated user, leading to unauthorized access to the administrator interface. This relates to handle_request in router/httpd/httpd.c and auth_check in web_hook.o. An attacker-supplied value of '\0' matches the device's default value of '\0' in some situations. Note: All versions of Lyra Mini and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability, Consumers can mitigate this vulnerability by disabling the remote access features from WAN. | 99% | 2 Jun 2025 |
| 9.8 critical | CVE-2025-4632 KEV | Samsung Electronics MagicINFO 9 Server Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority. | 24% | 22 May 2025 |
| 8.8 high | CVE-2025-4428 KEV | Ivanti Endpoint Manager Mobile Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests. | 87% | 19 May 2025 |
| 7.5 high | CVE-2025-4427 KEV | Ivanti Endpoint Manager Mobile An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API. | >99% | 19 May 2025 |
| 8.8 high | CVE-2025-27920 KEV | Srimax Output Messenger Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or arbitrary file access. | 1.9% | 19 May 2025 |
| 5.3 medium | CVE-2024-11182 KEV | MDaemon Email Server An XSS issue was discovered in MDaemon Email Server before version 24.5.1c. An attacker can send an HTML e-mail message with JavaScript in an img tag. This could allow a remote attacker to load arbitrary JavaScript code in the context of a webmail user's browser window. | 18% | 19 May 2025 |
| 6.1 medium | CVE-2024-27443 KEV | zimbra collaboration An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0. A Cross-Site Scripting (XSS) vulnerability exists in the CalendarInvite feature of the Zimbra webmail classic user interface, because of improper input validation in the handling of the calendar header. An attacker can exploit this via an email message containing a crafted calendar header with an embedded XSS payload. When a victim views this message in the Zimbra webmail classic interface, the payload is executed in the context of the victim's session, potentially leading to execution of arbitrary JavaScript code. | 24% | 19 May 2025 |
| 7.5 high | CVE-2023-38950 KEV | zkteco biotime A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read arbitrary files via supplying a crafted payload. This vulnerability was fixed in version 9.0.120240617.19506 of ZKBioTime. | 92% | 19 May 2025 |
| 9.1 critical | CVE-2025-42999 KEV | SAP_SE SAP NetWeaver (Visual Composer development server) SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system. | 14% | 15 May 2025 |
| 6.9 medium | CVE-2024-12987 KEV | DrayTek Vigor2960 A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component. | 98% | 15 May 2025 |
| 9.8 critical | CVE-2025-32756 KEV | Fortinet FortiNDR A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.7, FortiNDR 7.2.0 through 7.2.4, FortiNDR 7.0.0 through 7.0.6, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0.0 through 7.0.5, FortiRecorder 6.4.0 through 6.4.5, FortiVoice 7.2.0, FortiVoice 7.0.0 through 7.0.6, FortiVoice 6.4.0 through 6.4.10 allows a remote unauthenticated attacker to execute arbitrary code or commands via sending HTTP requests with specially crafted hash cookie. | 30% | 14 May 2025 |
| 7.8 high | CVE-2025-32709 KEV | Microsoft Windows 10 Version 1507 Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 2.2% | 13 May 2025 |
| 7.8 high | CVE-2025-32706 KEV | Microsoft Windows 10 Version 1507 Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 2.3% | 13 May 2025 |
| 7.8 high | CVE-2025-32701 KEV | Microsoft Windows 10 Version 1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | 1.4% | 13 May 2025 |
| 7.8 high | CVE-2025-30400 KEV | Microsoft Windows 10 Version 1809 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | 1.9% | 13 May 2025 |
| 7.5 high | CVE-2025-30397 KEV | Microsoft Windows 10 Version 1507 Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | 27% | 13 May 2025 |
| 4.9 medium | CVE-2025-47729 KEV | TeleMessage archiving backend The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025. | 0.45% | 12 May 2025 |
| 9.8 critical | CVE-2024-11120 KEV | GeoVision GV-VS12 Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has already been exploited by attackers, and we have received related reports. | 28% | 7 May 2025 |