Monthly Vuln Summary 2025-05 (24)
In-the-Wild CVE Review · 2025-05
24 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2025-4632 —
0.0— Samsung MagicINFO 9 Server — Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority. [KEV] - CVE-2023-38950 —
0.0— ZKTeco BioTime — ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload. [KEV] - CVE-2024-27443 —
0.0— Synacor Zimbra Collaboration Suite (ZCS) — Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vu… [KEV] - CVE-2025-27920 —
0.0— Srimax Output Messenger — Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to config… [KEV] - CVE-2024-11182 —
0.0— MDaemon Email Server — MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message. [KEV] - CVE-2025-4428 —
0.0— Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via craf… [KEV] - CVE-2025-4427 —
0.0— Ivanti Endpoint Manager Mobile (EPMM) — Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper cred… [KEV] - CVE-2025-42999 —
0.0— SAP NetWeaver — SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availab… [KEV] [RANSOMWARE] - CVE-2024-12987 —
0.0— DrayTek Vigor Routers — DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of t… [KEV] - CVE-2025-32756 —
0.0— Fortinet Multiple Products — Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or co… [KEV] - CVE-2025-32709 —
0.0— Microsoft Windows — Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. [KEV] - CVE-2025-30397 —
0.0— Microsoft Windows — Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. [KEV] - CVE-2025-32706 —
0.0— Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. [KEV] - CVE-2025-32701 —
0.0— Microsoft Windows — Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV] - CVE-2025-30400 —
0.0— Microsoft Windows — Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. [KEV] - CVE-2025-47729 —
0.0— TeleMessage TM SGNL — TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users. [KEV] - CVE-2024-11120 —
0.0— GeoVision Multiple Devices — Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacte… [KEV] - CVE-2024-6047 —
0.0— GeoVision Multiple Devices — Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacte… [KEV] - CVE-2025-27363 —
0.0— FreeType FreeType — FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary… [KEV] - CVE-2025-3248 —
0.0— Langflow Langflow — Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted … [KEV] [RANSOMWARE] - CVE-2025-34028 —
0.0— Commvault Command Center — Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code. [KEV] - CVE-2024-58136 —
0.0— Yiiframework Yii — Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other prod… [KEV] - CVE-2024-38475 —
0.0— Apache HTTP Server — Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served … [KEV] - CVE-2023-44221 —
0.0— SonicWall SMA100 Appliances — SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privi… [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.