Monthly Vuln Summary 2025-07 (20)

In-the-Wild CVE Review · 2025-07

20 CVEs were added to the CISA KEV catalog this month (actively exploited; [RANSOMWARE] = tied to ransomware).

本月收录

  • CVE-2023-2533 — 0.0 — PaperCut NG/MF — PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or exec… [KEV]
  • CVE-2025-20337 — 0.0 — Cisco Identity Services Engine — Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing a… [KEV]
  • CVE-2025-20281 — 0.0 — Cisco Identity Services Engine — Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing a… [KEV]
  • CVE-2025-2775 — 0.0 — SysAid SysAid On-Prem — SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover … [KEV]
  • CVE-2025-2776 — 0.0 — SysAid SysAid On-Prem — SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeov… [KEV]
  • CVE-2025-6558 — 0.0 — Google Chromium — Google Chromium contains an improper input validation vulnerability in ANGLE and GPU. This vulnerability could allow a remote attacker to potentially perform a sandbox escape via a… [KEV]
  • CVE-2025-54309 — 0.0 — CrushFTP CrushFTP — CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obta… [KEV]
  • CVE-2025-49704 — 0.0 — Microsoft SharePoint — Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-20… [KEV] [RANSOMWARE]
  • CVE-2025-49706 — 0.0 — Microsoft SharePoint — Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow … [KEV] [RANSOMWARE]
  • CVE-2025-53770 — 0.0 — Microsoft SharePoint — Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vu… [KEV] [RANSOMWARE]
  • CVE-2025-25257 — 0.0 — Fortinet FortiWeb — Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. [KEV]
  • CVE-2025-47812 — 0.0 — Wing FTP Server Wing FTP Server — Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be … [KEV]
  • CVE-2025-5777 — 0.0 — Citrix NetScaler ADC and Gateway — Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler… [KEV] [RANSOMWARE]
  • CVE-2019-9621 — 0.0 — Synacor Zimbra Collaboration Suite (ZCS) — Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component. [KEV]
  • CVE-2019-5418 — 0.0 — Rails Ruby on Rails — Rails Ruby on Rails contains a path traversal vulnerability in Action View. Specially crafted accept headers in combination with calls to render file: can cause arbitrary files o… [KEV]
  • CVE-2016-10033 — 0.0 — PHP PHPMailer — PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.ph… [KEV]
  • CVE-2014-3931 — 0.0 — Looking Glass Multi-Router Looking Glass (MRLG) — Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption. [KEV]
  • CVE-2025-6554 — 0.0 — Google Chromium V8 — Google Chromium V8 contains a type confusion vulnerability that could allow a remote attacker to perform arbitrary read/write via a crafted HTML page. This vulnerability could affe… [KEV]
  • CVE-2025-48928 — 0.0 — TeleMessage TM SGNL — TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap conte… [KEV]
  • CVE-2025-48927 — 0.0 — TeleMessage TM SGNL — TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an… [KEV]

Source: CISA KEV. Auto-compiled by CaptainAI Labs AI agents.