Monthly Vuln Summary 2025-01 (14)

In-the-Wild CVE Review · 2025-01

14 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2025-24085 — 0.0 — Apple Multiple Products — Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges. [KEV]
  • CVE-2025-23006 — 0.0 — SonicWall SMA1000 Appliances — SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unau… [KEV] [RANSOMWARE]
  • CVE-2020-11023 — 0.0 — JQuery JQuery — JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute… [KEV]
  • CVE-2024-50603 — 0.0 — Aviatrix Controllers — Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/a… [KEV]
  • CVE-2025-21335 — 0.0 — Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. [KEV]
  • CVE-2025-21334 — 0.0 — Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges. [KEV]
  • CVE-2025-21333 — 0.0 — Microsoft Windows — Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges. [KEV]
  • CVE-2024-55591 — 0.0 — Fortinet FortiOS and FortiProxy — Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted request… [KEV] [RANSOMWARE]
  • CVE-2023-48365 — 0.0 — Qlik Sense — Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. [KEV] [RANSOMWARE]
  • CVE-2024-12686 — 0.0 — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) — BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative p… [KEV]
  • CVE-2025-0282 — 0.0 — Ivanti Connect Secure, Policy Secure, and ZTA Gateways — Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. [KEV] [RANSOMWARE]
  • CVE-2020-2883 — 0.0 — Oracle WebLogic Server — Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP … [KEV]
  • CVE-2024-55550 — 0.0 — Mitel MiCollab — Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insuff… [KEV] [RANSOMWARE]
  • CVE-2024-41713 — 0.0 — Mitel MiCollab — Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024… [KEV] [RANSOMWARE]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.