Monthly Vuln Summary 2025-02 (27)
In-the-Wild CVE Review · 2025-02
27 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2023-34192 —
0.0— Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted scr… [KEV] - CVE-2024-49035 —
0.0— Microsoft Partner Center — Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. [KEV] - CVE-2024-20953 —
0.0— Oracle Agile Product Lifecycle Management (PLM) — Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system… [KEV] - CVE-2017-3066 —
0.0— Adobe ColdFusion — Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution. [KEV] - CVE-2025-24989 —
0.0— Microsoft Power Pages — Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user reg… [KEV] - CVE-2025-0111 —
0.0— Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the mana… [KEV] - CVE-2025-23209 —
0.0— Craft CMS Craft CMS — Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution. [KEV] - CVE-2025-0108 —
0.0— Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access… [KEV] - CVE-2024-53704 —
0.0— SonicWall SonicOS — SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication. [KEV] [RANSOMWARE] - CVE-2024-57727 —
0.0— SimpleHelp SimpleHelp — SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host… [KEV] [RANSOMWARE] - CVE-2025-24200 —
0.0— Apple iOS and iPadOS — Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device. [KEV] - CVE-2024-41710 —
0.0— Mitel SIP Phones — Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitizat… [KEV] - CVE-2024-40891 —
0.0— Zyxel DSL CPE Devices — Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS com… [KEV] - CVE-2024-40890 —
0.0— Zyxel DSL CPE Devices — Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands vi… [KEV] - CVE-2025-21418 —
0.0— Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain … [KEV] - CVE-2025-21391 —
0.0— Microsoft Windows — Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including dat… [KEV] - CVE-2025-0994 —
0.0— Trimble Cityworks — Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet… [KEV] - CVE-2020-15069 —
0.0— Sophos XG Firewall — Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature. [KEV] - CVE-2020-29574 —
0.0— Sophos CyberoamOS — CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely. [KEV] [RANSOMWARE] - CVE-2024-21413 —
0.0— Microsoft Office Outlook — Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker t… [KEV] - CVE-2022-23748 —
0.0— Audinate Dante Discovery — Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the … [KEV] - CVE-2025-0411 —
0.0— 7-Zip 7-Zip — 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of … [KEV] - CVE-2024-53104 —
0.0— Linux Kernel — Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of priv… [KEV] - CVE-2018-19410 —
0.0— Paessler PRTG Network Monitor — Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including adm… [KEV] - CVE-2018-9276 —
0.0— Paessler PRTG Network Monitor — Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administ… [KEV] - CVE-2024-29059 —
0.0— Microsoft .NET Framework — Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. [KEV] - CVE-2024-45195 —
0.0— Apache OFBiz — Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access. [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.