Monthly Vuln Summary 2025-05 (24)

In-the-Wild CVE Review · 2025-05

24 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2025-4632 — 0.0 — Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority. [KEV]
  • CVE-2023-38950 — 0.0 — ZKTeco BioTime — ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload. [KEV]
  • CVE-2024-27443 — 0.0 — Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vu… [KEV]
  • CVE-2025-27920 — 0.0 — Srimax Output Messenger — Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to config… [KEV]
  • CVE-2024-11182 — 0.0 — MDaemon Email Server — MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message. [KEV]
  • CVE-2025-4428 — 0.0 — Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via craf… [KEV]
  • CVE-2025-4427 — 0.0 — Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper cred… [KEV]
  • CVE-2025-42999 — 0.0 — SAP NetWeaver — SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availab… [KEV] [RANSOMWARE]
  • CVE-2024-12987 — 0.0 — DrayTek Vigor Routers — DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of t… [KEV]
  • CVE-2025-32756 — 0.0 — Fortinet Multiple Products — Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or co… [KEV]
  • CVE-2025-32709 — 0.0 — Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. [KEV]
  • CVE-2025-30397 — 0.0 — Microsoft Windows — Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. [KEV]
  • CVE-2025-32706 — 0.0 — Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2025-32701 — 0.0 — Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2025-30400 — 0.0 — Microsoft Windows — Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2025-47729 — 0.0 — TeleMessage TM SGNL — TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users. [KEV]
  • CVE-2024-11120 — 0.0 — GeoVision Multiple Devices — Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacte… [KEV]
  • CVE-2024-6047 — 0.0 — GeoVision Multiple Devices — Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacte… [KEV]
  • CVE-2025-27363 — 0.0 — FreeType FreeType — FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary… [KEV]
  • CVE-2025-3248 — 0.0 — Langflow Langflow — Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted … [KEV] [RANSOMWARE]
  • CVE-2025-34028 — 0.0 — Commvault Command Center — Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code. [KEV]
  • CVE-2024-58136 — 0.0 — Yiiframework Yii — Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other prod… [KEV]
  • CVE-2024-38475 — 0.0 — Apache HTTP Server — Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served … [KEV]
  • CVE-2023-44221 — 0.0 — SonicWall SMA100 Appliances — SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privi… [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.