CISA Known Exploited Vulnerabilities
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
The KEV catalog lists vulnerabilities that are known to be actively exploited in the wild. Federal agencies are required to remediate these on defined deadlines.
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-43300 | UNKNOWN | — | Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework. | Aug 21, 2025 |
| CVE-2025-54948 | UNKNOWN | — | Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. | Aug 18, 2025 |
| CVE-2025-8876 | UNKNOWN | — | N-able N-Central contains a command injection vulnerability via improper sanitization of user input. | Aug 13, 2025 |
| CVE-2025-8875 | UNKNOWN | — | N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution. | Aug 13, 2025 |
| CVE-2007-0671 | UNKNOWN | — | Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system. | Aug 12, 2025 |
| CVE-2013-3893 | UNKNOWN | — | Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | Aug 12, 2025 |
| CVE-2020-25078 | UNKNOWN | — | D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | Aug 5, 2025 |
| CVE-2022-40799 | UNKNOWN | — | D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | Aug 5, 2025 |
| CVE-2020-25079 | UNKNOWN | — | D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. | Aug 5, 2025 |
| CVE-2025-20281 | UNKNOWN | — | Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. | Jul 28, 2025 |
| CVE-2023-2533 | UNKNOWN | — | PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code. | Jul 28, 2025 |
| CVE-2025-20337 | UNKNOWN | — | Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. | Jul 28, 2025 |
| CVE-2025-49704 | UNKNOWN | — | Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. | Jul 22, 2025 |
| CVE-2025-6558 | UNKNOWN | — | Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Jul 22, 2025 |
| CVE-2025-54309 | UNKNOWN | — | CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS. | Jul 22, 2025 |
| CVE-2025-2776 | UNKNOWN | — | SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives. | Jul 22, 2025 |
| CVE-2025-2775 | UNKNOWN | — | SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives. | Jul 22, 2025 |
| CVE-2025-25257 | UNKNOWN | — | Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. | Jul 18, 2025 |
| CVE-2025-47812 | UNKNOWN | — | Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arbitrary system commands with the privileges of the FTP service (root or SYSTEM by default). | Jul 14, 2025 |
| CVE-2019-5418 | UNKNOWN | — | Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to `render file:` can cause arbitrary files on the target server to be rendered, disclosing the file contents. | Jul 7, 2025 |
| CVE-2019-9621 | UNKNOWN | — | Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component. | Jul 7, 2025 |
| CVE-2016-10033 | UNKNOWN | — | PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition. | Jul 7, 2025 |
| CVE-2014-3931 | UNKNOWN | — | Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption. | Jul 7, 2025 |
| CVE-2025-6554 | UNKNOWN | — | Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Jul 2, 2025 |
| CVE-2025-48927 | UNKNOWN | — | TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump endpoint at a /heapdump URI. | Jul 1, 2025 |