Monthly Vuln Summary 2025-03 (32)

In-the-Wild CVE Review · 2025-03

32 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2024-20439 — 0.0 — Cisco Smart Licensing Utility — Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative cre… [KEV]
  • CVE-2025-2783 — 0.0 — Google Chromium Mojo — Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances.… [KEV]
  • CVE-2019-9875 — 0.0 — Sitecore CMS and Experience Platform (XP) — Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrar… [KEV]
  • CVE-2019-9874 — 0.0 — Sitecore CMS and Experience Platform (XP) — Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitr… [KEV]
  • CVE-2025-30154 — 0.0 — reviewdog action-setup GitHub Action — reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs. [KEV]
  • CVE-2017-12637 — 0.0 — SAP NetWeaver — SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read… [KEV]
  • CVE-2024-48248 — 0.0 — NAKIVO Backup and Replication — NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files. [KEV]
  • CVE-2025-1316 — 0.0 — Edimax IC-7100 IP Camera — Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially cr… [KEV]
  • CVE-2025-30066 — 0.0 — tj-actions changed-files GitHub Action — tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. … [KEV]
  • CVE-2025-24472 — 0.0 — Fortinet FortiOS and FortiProxy — Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests. [KEV] [RANSOMWARE]
  • CVE-2025-21590 — 0.0 — Juniper Junos OS — Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary cod… [KEV]
  • CVE-2025-24201 — 0.0 — Apple Multiple Products — Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content… [KEV]
  • CVE-2025-24993 — 0.0 — Microsoft Windows — Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. [KEV]
  • CVE-2025-24991 — 0.0 — Microsoft Windows — Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. [KEV]
  • CVE-2025-24985 — 0.0 — Microsoft Windows — Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. [KEV]
  • CVE-2025-24984 — 0.0 — Microsoft Windows — Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose info… [KEV]
  • CVE-2025-24983 — 0.0 — Microsoft Windows — Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV]
  • CVE-2025-26633 — 0.0 — Microsoft Windows — Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. [KEV] [RANSOMWARE]
  • CVE-2024-13161 — 0.0 — Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. [KEV]
  • CVE-2024-13160 — 0.0 — Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. [KEV]
  • CVE-2024-13159 — 0.0 — Ivanti Endpoint Manager (EPM) — Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. [KEV]
  • CVE-2024-57968 — 0.0 — Advantive VeraCore — Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. [KEV]
  • CVE-2025-25181 — 0.0 — Advantive VeraCore — Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. [KEV]
  • CVE-2025-22226 — 0.0 — VMware ESXi, Workstation, and Fusion — VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administr… [KEV]
  • CVE-2025-22225 — 0.0 — VMware ESXi — VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leadin… [KEV] [RANSOMWARE]
  • CVE-2025-22224 — 0.0 — VMware ESXi and Workstation — VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attac… [KEV]
  • CVE-2024-50302 — 0.0 — Linux Kernel — The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report. [KEV]
  • CVE-2024-4885 — 0.0 — Progress WhatsUp Gold — Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution. [KEV]
  • CVE-2018-8639 — 0.0 — Microsoft Windows — Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exp… [KEV] [RANSOMWARE]
  • CVE-2022-43769 — 0.0 — Hitachi Vantara Pentaho Business Analytics (BA) Server — Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrar… [KEV]
  • CVE-2022-43939 — 0.0 — Hitachi Vantara Pentaho Business Analytics (BA) Server — Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization. [KEV]
  • CVE-2023-20118 — 0.0 — Cisco Small Business RV Series Routers — Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticat… [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.