CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2024-20439

Cisco Smart Licensing Utility Static Credential Vulnerability

Vendor: Cisco

Product: Smart Licensing Utility

Added: 2025-03-31

Due Date: 2025-04-21

Description:

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-912

CVE-2025-2783

Google Chromium Mojo Sandbox Escape Vulnerability

Vendor: Google

Product: Chromium Mojo

Added: 2025-03-27

Due Date: 2025-04-17

Description:

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-9875

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Vendor: Sitecore

Product: CMS and Experience Platform (XP)

Added: 2025-03-26

Due Date: 2025-04-16

Description:

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2019-9874

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Vendor: Sitecore

Product: CMS and Experience Platform (XP)

Added: 2025-03-26

Due Date: 2025-04-16

Description:

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-30154

reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

Vendor: reviewdog

Product: action-setup GitHub Action

Added: 2025-03-24

Due Date: 2025-04-14

Description:

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

Required Action:

Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-506

CVE-2017-12637

SAP NetWeaver Directory Traversal Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2025-03-19

Due Date: 2025-04-09

Description:

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2024-48248

NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

Vendor: NAKIVO

Product: Backup and Replication

Added: 2025-03-19

Due Date: 2025-04-09

Description:

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-36

CVE-2025-1316

Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Vendor: Edimax

Product: IC-7100 IP Camera

Added: 2025-03-19

Due Date: 2025-04-09

Description:

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-30066

tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

Vendor: tj-actions

Product: changed-files GitHub Action

Added: 2025-03-18

Due Date: 2025-04-08

Description:

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

Required Action:

Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-506

CVE-2025-24472

Ransomware

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Vendor: Fortinet

Product: FortiOS and FortiProxy

Added: 2025-03-18

Due Date: 2025-04-08

Description:

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-288

CVE-2025-21590

Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

Vendor: Juniper

Product: Junos OS

Added: 2025-03-13

Due Date: 2025-04-03

Description:

Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-653

CVE-2025-24201

Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-03-13

Due Date: 2025-04-03

Description:

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-24993

Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-03-11

Due Date: 2025-04-01

Description:

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-122

CVE-2025-24991

Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-03-11

Due Date: 2025-04-01

Description:

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-125

CVE-2025-24985

Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-03-11

Due Date: 2025-04-01

Description:

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-190 CWE-122