CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2020-15069

Sophos XG Firewall Buffer Overflow Vulnerability

Vendor: Sophos

Product: XG Firewall

Added: 2025-02-06

Due Date: 2025-02-27

Description:

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-120

CVE-2020-29574

CyberoamOS (CROS) SQL Injection Vulnerability

Vendor: Sophos

Product: CyberoamOS

Added: 2025-02-06

Due Date: 2025-02-27

Description:

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

Required Action:

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CWEs:

CWE-89

CVE-2024-21413

Microsoft Outlook Improper Input Validation Vulnerability

Vendor: Microsoft

Product: Office Outlook

Added: 2025-02-06

Due Date: 2025-02-27

Description:

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-20

CVE-2022-23748

Dante Discovery Process Control Vulnerability

Vendor: Audinate

Product: Dante Discovery

Added: 2025-02-06

Due Date: 2025-02-27

Description:

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-114

CVE-2025-0411

7-Zip Mark of the Web Bypass Vulnerability

Vendor: 7-Zip

Product: 7-Zip

Added: 2025-02-06

Due Date: 2025-02-27

Description:

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-693

CVE-2024-53104

Linux Kernel Out-of-Bounds Write Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-02-05

Due Date: 2025-02-26

Description:

Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2018-19410

Paessler PRTG Network Monitor Local File Inclusion Vulnerability

Vendor: Paessler

Product: PRTG Network Monitor

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-9276

Paessler PRTG Network Monitor OS Command Injection Vulnerability

Vendor: Paessler

Product: PRTG Network Monitor

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2024-29059

Microsoft .NET Framework Information Disclosure Vulnerability

Vendor: Microsoft

Product: .NET Framework

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-209

CVE-2024-45195

Apache OFBiz Forced Browsing Vulnerability

Vendor: Apache

Product: OFBiz

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-425

CVE-2025-24085

Apple Multiple Products Use-After-Free Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-01-29

Due Date: 2025-02-19

Description:

Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2025-23006

Ransomware

SonicWall SMA1000 Appliances Deserialization Vulnerability

Vendor: SonicWall

Product: SMA1000 Appliances

Added: 2025-01-24

Due Date: 2025-02-14

Description:

SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2020-11023

JQuery Cross-Site Scripting (XSS) Vulnerability

Vendor: JQuery

Product: JQuery

Added: 2025-01-23

Due Date: 2025-02-13

Description:

JQuery contains a persistent cross-site scripting (XSS) vulnerability. When passing maliciously formed, untrusted input enclosed in HTML tags, JQuery's DOM manipulators can execute untrusted code in the context of the user's browser.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-79

CVE-2024-50603

Aviatrix Controllers OS Command Injection Vulnerability

Vendor: Aviatrix

Product: Controllers

Added: 2025-01-16

Due Date: 2025-02-06

Description:

Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-21335

Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-01-14

Due Date: 2025-02-04

Description:

Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416