CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2024-6047

GeoVision Devices OS Command Injection Vulnerability

Vendor: GeoVision

Product: Multiple Devices

Added: 2025-05-07

Due Date: 2025-05-28

Description:

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-27363

FreeType Out-of-Bounds Write Vulnerability

Vendor: FreeType

Product: FreeType

Added: 2025-05-06

Due Date: 2025-05-27

Description:

FreeType contains an out-of-bounds write vulnerability when attempting to parse font subglyph structures related to TrueType GX and variable font files that may allow for arbitrary code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-3248

Langflow Missing Authentication Vulnerability

Vendor: Langflow

Product: Langflow

Added: 2025-05-05

Due Date: 2025-05-26

Description:

Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-306

CVE-2025-34028

Commvault Command Center Path Traversal Vulnerability

Vendor: Commvault

Product: Command Center

Added: 2025-05-02

Due Date: 2025-05-23

Description:

Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2024-58136

Yiiframework Yii Improper Protection of Alternate Path Vulnerability

Vendor: Yiiframework

Product: Yii

Added: 2025-05-02

Due Date: 2025-05-23

Description:

Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-424

CVE-2024-38475

Apache HTTP Server Improper Escaping of Output Vulnerability

Vendor: Apache

Product: HTTP Server

Added: 2025-05-01

Due Date: 2025-05-22

Description:

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-116

CVE-2023-44221

SonicWall SMA100 Appliances OS Command Injection Vulnerability

Vendor: SonicWall

Product: SMA100 Appliances

Added: 2025-05-01

Due Date: 2025-05-22

Description:

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2025-31324

Ransomware

SAP NetWeaver Unrestricted File Upload Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2025-04-29

Due Date: 2025-05-20

Description:

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-434

CVE-2025-1976

Broadcom Brocade Fabric OS Code Injection Vulnerability

Vendor: Broadcom

Product: Brocade Fabric OS

Added: 2025-04-28

Due Date: 2025-05-19

Description:

Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-94

CVE-2025-42599

Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

Vendor: Qualitia

Product: Active! Mail

Added: 2025-04-28

Due Date: 2025-05-19

Description:

Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted request.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-121

CVE-2025-3928

Commvault Web Server Unspecified Vulnerability

Vendor: Commvault

Product: Web Server

Added: 2025-04-28

Due Date: 2025-05-19

Description:

Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24054

Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-04-17

Due Date: 2025-05-08

Description:

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-73

CVE-2025-31201

Apple Multiple Products Arbitrary Read and Write Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-04-17

Due Date: 2025-05-08

Description:

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-31200

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-04-17

Due Date: 2025-05-08

Description:

Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-20035

SonicWall SMA100 Appliances OS Command Injection Vulnerability

Vendor: SonicWall

Product: SMA100 Appliances

Added: 2025-04-16

Due Date: 2025-05-07

Description:

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78