Known exploited vulnerabilities
Vulnerabilities CISA has confirmed are being exploited, newest additions first — with the remediation deadline federal agencies must meet.
| Score | CVE | Affected | EPSS | Added to KEV |
|---|---|---|---|---|
| 8.1 high | CVE-2025-23209 KEV | craftcms cms Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue. | 22% | 20 Feb 2025 |
| 8.8 high | CVE-2025-0108 KEV | Palo Alto Networks Cloud NGFW An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS. You can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 . This issue does not affect Cloud NGFW or Prisma Access software. | 98% | 18 Feb 2025 |
| 9.8 critical | CVE-2024-53704 KEV | SonicWall SonicOS An Improper Authentication vulnerability in the SSLVPN authentication mechanism allows a remote attacker to bypass authentication. | 95% | 18 Feb 2025 |
| 7.5 high | CVE-2024-57727 KEV | simple-help simplehelp SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files include server configuration files containing various secrets and hashed user passwords. | 97% | 13 Feb 2025 |
| 6.1 medium | CVE-2025-24200 KEV | Apple iOS and iPadOS An authorization issue was addressed with improved state management. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals. | 4.4% | 12 Feb 2025 |
| 7.2 high | CVE-2024-41710 KEV | mitel 6940_sip_firmware A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, through R6.4.0.HF1 (R6.4.0.136) could allow an authenticated attacker with administrative privilege to conduct an argument injection attack, due to insufficient parameter sanitization during the boot process. A successful exploit could allow an attacker to execute arbitrary commands within the context of the system. | 42% | 12 Feb 2025 |
| 7.8 high | CVE-2025-21418 KEV | Microsoft Windows 10 Version 1507 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 1.6% | 11 Feb 2025 |
| 7.1 high | CVE-2025-21391 KEV | Microsoft Windows 10 Version 1507 Windows Storage Elevation of Privilege Vulnerability | 2.3% | 11 Feb 2025 |
| 8.8 high | CVE-2024-40891 KEV | Zyxel VMG4325-B10A firmware **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device via Telnet. | 22% | 11 Feb 2025 |
| 8.8 high | CVE-2024-40890 KEV | Zyxel VMG4325-B10A firmware **UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute operating system (OS) commands on an affected device by sending a crafted HTTP POST request. | 21% | 11 Feb 2025 |
| 8.6 high | CVE-2025-0994 KEV | Trimble Cityworks Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server. | 31% | 7 Feb 2025 |
| 7.0 high | CVE-2025-0411 KEV | 7-Zip 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456. | 67% | 6 Feb 2025 |
| 9.8 critical | CVE-2024-21413 KEV | Microsoft 365 Apps for Enterprise Microsoft Outlook Remote Code Execution Vulnerability | 95% | 6 Feb 2025 |
| 7.8 high | CVE-2022-23748 KEV | Audinate Dante Application Library for Windows mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files. | 9.1% | 6 Feb 2025 |
| 9.8 critical | CVE-2020-29574 KEV | sophos cyberoamos An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely. | 4.7% | 6 Feb 2025 |
| 9.8 critical | CVE-2020-15069 KEV | sophos xg firewall firmware Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x. | 11% | 6 Feb 2025 |
| 7.8 high | CVE-2024-53104 KEV | Linux In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Skip parsing frames of type UVC_VS_UNDEFINED in uvc_parse_format This can lead to out of bounds writes since frames of this type were not taken into account when calculating the size of the frames buffer in uvc_parse_streaming. | 3.4% | 5 Feb 2025 |
| 7.5 high | CVE-2024-45195 KEV | Apache Software Foundation Apache OFBiz Direct Request ('Forced Browsing') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. | >99% | 4 Feb 2025 |
| 7.5 high | CVE-2024-29059 KEV | Microsoft .NET Framework 4.8 .NET Framework Information Disclosure Vulnerability | 99% | 4 Feb 2025 |
| 9.8 critical | CVE-2018-19410 KEV | paessler prtg network monitor PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator). | 98% | 4 Feb 2025 |