Monthly Vuln Summary 2025-02 (27)

In-the-Wild CVE Review · 2025-02

27 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2023-34192 — 0.0 — Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted scr… [KEV]
  • CVE-2024-49035 — 0.0 — Microsoft Partner Center — Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. [KEV]
  • CVE-2024-20953 — 0.0 — Oracle Agile Product Lifecycle Management (PLM) — Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system… [KEV]
  • CVE-2017-3066 — 0.0 — Adobe ColdFusion — Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. [KEV]
  • CVE-2025-24989 — 0.0 — Microsoft Power Pages — Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user reg… [KEV]
  • CVE-2025-0111 — 0.0 — Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the mana… [KEV]
  • CVE-2025-23209 — 0.0 — Craft CMS Craft CMS — Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution. [KEV]
  • CVE-2025-0108 — 0.0 — Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access… [KEV]
  • CVE-2024-53704 — 0.0 — SonicWall SonicOS — SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. [KEV] [RANSOMWARE]
  • CVE-2024-57727 — 0.0 — SimpleHelp SimpleHelp — SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host… [KEV] [RANSOMWARE]
  • CVE-2025-24200 — 0.0 — Apple iOS and iPadOS — Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. [KEV]
  • CVE-2024-41710 — 0.0 — Mitel SIP Phones — Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitizat… [KEV]
  • CVE-2024-40891 — 0.0 — Zyxel DSL CPE Devices — Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS com… [KEV]
  • CVE-2024-40890 — 0.0 — Zyxel DSL CPE Devices — Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands vi… [KEV]
  • CVE-2025-21418 — 0.0 — Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain … [KEV]
  • CVE-2025-21391 — 0.0 — Microsoft Windows — Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including dat… [KEV]
  • CVE-2025-0994 — 0.0 — Trimble Cityworks — Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet… [KEV]
  • CVE-2020-15069 — 0.0 — Sophos XG Firewall — Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. [KEV]
  • CVE-2020-29574 — 0.0 — Sophos CyberoamOS — CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. [KEV] [RANSOMWARE]
  • CVE-2024-21413 — 0.0 — Microsoft Office Outlook — Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker t… [KEV]
  • CVE-2022-23748 — 0.0 — Audinate Dante Discovery — Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the … [KEV]
  • CVE-2025-0411 — 0.0 — 7-Zip 7-Zip — 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of … [KEV]
  • CVE-2024-53104 — 0.0 — Linux Kernel — Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of priv… [KEV]
  • CVE-2018-19410 — 0.0 — Paessler PRTG Network Monitor — Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including adm… [KEV]
  • CVE-2018-9276 — 0.0 — Paessler PRTG Network Monitor — Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administ… [KEV]
  • CVE-2024-29059 — 0.0 — Microsoft .NET Framework — Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. [KEV]
  • CVE-2024-45195 — 0.0 — Apache OFBiz — Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.