Monthly Vuln Summary 2025-03 (32)
In-the-Wild CVE Review · 2025-03
32 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2024-20439 —
0.0— Cisco Smart Licensing Utility — Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative cre… [KEV] - CVE-2025-2783 —
0.0— Google Chromium Mojo — Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances.… [KEV] - CVE-2019-9875 —
0.0— Sitecore CMS and Experience Platform (XP) — Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrar… [KEV] - CVE-2019-9874 —
0.0— Sitecore CMS and Experience Platform (XP) — Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitr… [KEV] - CVE-2025-30154 —
0.0— reviewdog action-setup GitHub Action — reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs. [KEV] - CVE-2017-12637 —
0.0— SAP NetWeaver — SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read… [KEV] - CVE-2024-48248 —
0.0— NAKIVO Backup and Replication — NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files. [KEV] - CVE-2025-1316 —
0.0— Edimax IC-7100 IP Camera — Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially cr… [KEV] - CVE-2025-30066 —
0.0— tj-actions changed-files GitHub Action — tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. … [KEV] - CVE-2025-24472 —
0.0— Fortinet FortiOS and FortiProxy — Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. [KEV] [RANSOMWARE] - CVE-2025-21590 —
0.0— Juniper Junos OS — Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary cod… [KEV] - CVE-2025-24201 —
0.0— Apple Multiple Products — Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content… [KEV] - CVE-2025-24993 —
0.0— Microsoft Windows — Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. [KEV] - CVE-2025-24991 —
0.0— Microsoft Windows — Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. [KEV] - CVE-2025-24985 —
0.0— Microsoft Windows — Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. [KEV] - CVE-2025-24984 —
0.0— Microsoft Windows — Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose info… [KEV] - CVE-2025-24983 —
0.0— Microsoft Windows — Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV] - CVE-2025-26633 —
0.0— Microsoft Windows — Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. [KEV] [RANSOMWARE] - CVE-2024-13161 —
0.0— Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. [KEV] - CVE-2024-13160 —
0.0— Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. [KEV] - CVE-2024-13159 —
0.0— Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. [KEV] - CVE-2024-57968 —
0.0— Advantive VeraCore — Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. [KEV] - CVE-2025-25181 —
0.0— Advantive VeraCore — Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. [KEV] - CVE-2025-22226 —
0.0— VMware ESXi, Workstation, and Fusion — VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administr… [KEV] - CVE-2025-22225 —
0.0— VMware ESXi — VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leadin… [KEV] [RANSOMWARE] - CVE-2025-22224 —
0.0— VMware ESXi and Workstation — VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attac… [KEV] - CVE-2024-50302 —
0.0— Linux Kernel — The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. [KEV] - CVE-2024-4885 —
0.0— Progress WhatsUp Gold — Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. [KEV] - CVE-2018-8639 —
0.0— Microsoft Windows — Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exp… [KEV] [RANSOMWARE] - CVE-2022-43769 —
0.0— Hitachi Vantara Pentaho Business Analytics (BA) Server — Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrar… [KEV] - CVE-2022-43939 —
0.0— Hitachi Vantara Pentaho Business Analytics (BA) Server — Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. [KEV] - CVE-2023-20118 —
0.0— Cisco Small Business RV Series Routers — Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticat… [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.