CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2025-30397

Microsoft Windows Scripting Engine Type Confusion Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-05-13

Due Date: 2025-06-03

Description:

Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-843

CVE-2025-32706

Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-05-13

Due Date: 2025-06-03

Description:

Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-122

CVE-2025-32701

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-05-13

Due Date: 2025-06-03

Description:

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2025-30400

Microsoft Windows DWM Core Library Use-After-Free Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-05-13

Due Date: 2025-06-03

Description:

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2025-47729

TeleMessage TM SGNL Hidden Functionality Vulnerability

Vendor: TeleMessage

Product: TM SGNL

Added: 2025-05-12

Due Date: 2025-06-02

Description:

TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-912

CVE-2024-11120

GeoVision Devices OS Command Injection Vulnerability

Vendor: GeoVision

Product: Multiple Devices

Added: 2025-05-07

Due Date: 2025-05-28

Description:

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2024-6047

GeoVision Devices OS Command Injection Vulnerability

Vendor: GeoVision

Product: Multiple Devices

Added: 2025-05-07

Due Date: 2025-05-28

Description:

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-27363

FreeType Out-of-Bounds Write Vulnerability

Vendor: FreeType

Product: FreeType

Added: 2025-05-06

Due Date: 2025-05-27

Description:

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-3248

Langflow Missing Authentication Vulnerability

Vendor: Langflow

Product: Langflow

Added: 2025-05-05

Due Date: 2025-05-26

Description:

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-306

CVE-2025-34028

Commvault Command Center Path Traversal Vulnerability

Vendor: Commvault

Product: Command Center

Added: 2025-05-02

Due Date: 2025-05-23

Description:

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2024-58136

Yiiframework Yii Improper Protection of Alternate Path Vulnerability

Vendor: Yiiframework

Product: Yii

Added: 2025-05-02

Due Date: 2025-05-23

Description:

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-424

CVE-2024-38475

Apache HTTP Server Improper Escaping of Output Vulnerability

Vendor: Apache

Product: HTTP Server

Added: 2025-05-01

Due Date: 2025-05-22

Description:

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-116

CVE-2023-44221

SonicWall SMA100 Appliances OS Command Injection Vulnerability

Vendor: SonicWall

Product: SMA100 Appliances

Added: 2025-05-01

Due Date: 2025-05-22

Description:

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-31324

Ransomware

SAP NetWeaver Unrestricted File Upload Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2025-04-29

Due Date: 2025-05-20

Description:

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-434

CVE-2025-1976

Broadcom Brocade Fabric OS Code Injection Vulnerability

Vendor: Broadcom

Product: Brocade Fabric OS

Added: 2025-04-28

Due Date: 2025-05-19

Description:

Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94