Monthly Vuln Summary 2025-06 (20)
In-the-Wild CVE Review · 2025-06
20 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).
本月收录
- CVE-2025-6543 —
0.0— Citrix NetScaler ADC and Gateway — Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virt… [KEV] - CVE-2019-6693 —
0.0— Fortinet FortiOS — Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of … [KEV] [RANSOMWARE] - CVE-2024-0769 —
0.0— D-Link DIR-859 Router — D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the inpu… [KEV] - CVE-2024-54085 —
0.0— AMI MegaRAC SPx — AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of con… [KEV] - CVE-2023-0386 —
0.0— Linux Kernel — Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’… [KEV] - CVE-2023-33538 —
0.0— TP-Link Multiple Routers — TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be e… [KEV] - CVE-2025-43200 —
0.0— Apple Multiple Products — Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link. [KEV] - CVE-2025-33053 —
0.0— Microsoft Windows — Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the Workin… [KEV] - CVE-2025-24016 —
0.0— Wazuh Wazuh Server — Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers. [KEV] - CVE-2024-42009 —
0.0— Roundcube Webmail — RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message … [KEV] - CVE-2025-32433 —
0.0— Erlang Erlang/OTP — Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credent… [KEV] - CVE-2025-5419 —
0.0— Google Chromium V8 — Google Chromium V8 contains an out-of-bounds read and write vulnerability that could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vu… [KEV] - CVE-2025-21479 —
0.0— Qualcomm Multiple Chipsets — Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode … [KEV] - CVE-2025-21480 —
0.0— Qualcomm Multiple Chipsets — Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode … [KEV] - CVE-2025-27038 —
0.0— Qualcomm Multiple Chipsets — Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome. [KEV] - CVE-2021-32030 —
0.0— ASUS Routers — ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The … [KEV] - CVE-2025-3935 —
0.0— ConnectWise ScreenConnect — ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code executi… [KEV] - CVE-2025-35939 —
0.0— Craft CMS Craft CMS — Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, suc… [KEV] - CVE-2024-56145 —
0.0— Craft CMS Craft CMS — Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration hasregister_argc_argvenab… [KEV] - CVE-2023-39780 —
0.0— ASUS RT-AX55 Routers — ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346… [KEV]
Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.