CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2024-40890

Zyxel DSL CPE OS Command Injection Vulnerability

Vendor: Zyxel

Product: DSL CPE Devices

Added: 2025-02-11

Due Date: 2025-03-04

Description:

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.

Required Action:

The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization if a current mitigation is unavailable.

CWEs:

CWE-78

CVE-2025-21418

Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-02-11

Due Date: 2025-03-04

Description:

Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-122

CVE-2025-21391

Microsoft Windows Storage Link Following Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-02-11

Due Date: 2025-03-04

Description:

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-59

CVE-2025-0994

Trimble Cityworks Deserialization Vulnerability

Vendor: Trimble

Product: Cityworks

Added: 2025-02-07

Due Date: 2025-02-28

Description:

Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Services (IIS) web server.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2020-15069

Sophos XG Firewall Buffer Overflow Vulnerability

Vendor: Sophos

Product: XG Firewall

Added: 2025-02-06

Due Date: 2025-02-27

Description:

Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-120

CVE-2020-29574

CyberoamOS (CROS) SQL Injection Vulnerability

Vendor: Sophos

Product: CyberoamOS

Added: 2025-02-06

Due Date: 2025-02-27

Description:

CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.

Required Action:

The impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

CWEs:

CWE-89

CVE-2024-21413

Microsoft Outlook Improper Input Validation Vulnerability

Vendor: Microsoft

Product: Office Outlook

Added: 2025-02-06

Due Date: 2025-02-27

Description:

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-20

CVE-2022-23748

Dante Discovery Process Control Vulnerability

Vendor: Audinate

Product: Dante Discovery

Added: 2025-02-06

Due Date: 2025-02-27

Description:

Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application Library to execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-114

CVE-2025-0411

7-Zip Mark of the Web Bypass Vulnerability

Vendor: 7-Zip

Product: 7-Zip

Added: 2025-02-06

Due Date: 2025-02-27

Description:

7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-693

CVE-2024-53104

Linux Kernel Out-of-Bounds Write Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-02-05

Due Date: 2025-02-26

Description:

Linux kernel contains an out-of-bounds write vulnerability in the uvc_parse_streaming component of the USB Video Class (UVC) driver that could allow for physical escalation of privilege.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2018-19410

Paessler PRTG Network Monitor Local File Inclusion Vulnerability

Vendor: Paessler

Product: PRTG Network Monitor

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-9276

Paessler PRTG Network Monitor OS Command Injection Vulnerability

Vendor: Paessler

Product: PRTG Network Monitor

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78

CVE-2024-29059

Microsoft .NET Framework Information Disclosure Vulnerability

Vendor: Microsoft

Product: .NET Framework

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-209

CVE-2024-45195

Apache OFBiz Forced Browsing Vulnerability

Vendor: Apache

Product: OFBiz

Added: 2025-02-04

Due Date: 2025-02-25

Description:

Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-425

CVE-2025-24085

Apple Multiple Products Use-After-Free Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2025-01-29

Due Date: 2025-02-19

Description:

Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.

Required Action:

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416