Monthly Vuln Summary 2025-04 (15)

In-the-Wild CVE Review · 2025-04

15 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2025-31324 — 0.0 — SAP NetWeaver — SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable b… [KEV] [RANSOMWARE]
  • CVE-2025-1976 — 0.0 — Broadcom Brocade Fabric OS — Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges. [KEV]
  • CVE-2025-42599 — 0.0 — Qualitia Active! Mail — Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a … [KEV]
  • CVE-2025-3928 — 0.0 — Commvault Web Server — Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells. [KEV]
  • CVE-2025-24054 — 0.0 — Microsoft Windows — Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network. [KEV]
  • CVE-2025-31201 — 0.0 — Apple Multiple Products — Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication. [KEV]
  • CVE-2025-31200 — 0.0 — Apple Multiple Products — Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted… [KEV]
  • CVE-2021-20035 — 0.0 — SonicWall SMA100 Appliances — SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a … [KEV]
  • CVE-2024-53150 — 0.0 — Linux Kernel — Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information. [KEV]
  • CVE-2024-53197 — 0.0 — Linux Kernel — Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to pote… [KEV]
  • CVE-2025-29824 — 0.0 — Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV] [RANSOMWARE]
  • CVE-2025-30406 — 0.0 — Gladinet CentreStack — Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification… [KEV]
  • CVE-2025-31161 — 0.0 — CrushFTP CrushFTP — CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable us… [KEV] [RANSOMWARE]
  • CVE-2025-22457 — 0.0 — Ivanti Connect Secure, Policy Secure, and ZTA Gateways — Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code exe… [KEV] [RANSOMWARE]
  • CVE-2025-24813 — 0.0 — Apache Tomcat — Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. … [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.