CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2024-53150

Linux Kernel Out-of-Bounds Read Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-04-09

Due Date: 2025-04-30

Description:

Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-125

CVE-2024-53197

Linux Kernel Out-of-Bounds Access Vulnerability

Vendor: Linux

Product: Kernel

Added: 2025-04-09

Due Date: 2025-04-30

Description:

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-787

CVE-2025-29824

Ransomware

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2025-04-08

Due Date: 2025-04-29

Description:

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-416

CVE-2025-30406

Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

Vendor: Gladinet

Product: CentreStack

Added: 2025-04-08

Due Date: 2025-04-29

Description:

Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-321

CVE-2025-31161

Ransomware

CrushFTP Authentication Bypass Vulnerability

Vendor: CrushFTP

Product: CrushFTP

Added: 2025-04-07

Due Date: 2025-04-28

Description:

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-305

CVE-2025-22457

Ransomware

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Vendor: Ivanti

Product: Connect Secure, Policy Secure, and ZTA Gateways

Added: 2025-04-04

Due Date: 2025-04-11

Description:

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

Required Action:

Apply mitigations as set forth in the CISA instructions linked below.

CWEs:

CWE-121

CVE-2025-24813

Apache Tomcat Path Equivalence Vulnerability

Vendor: Apache

Product: Tomcat

Added: 2025-04-01

Due Date: 2025-04-22

Description:

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-44 CWE-502

CVE-2024-20439

Cisco Smart Licensing Utility Static Credential Vulnerability

Vendor: Cisco

Product: Smart Licensing Utility

Added: 2025-03-31

Due Date: 2025-04-21

Description:

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-912

CVE-2025-2783

Google Chromium Mojo Sandbox Escape Vulnerability

Vendor: Google

Product: Chromium Mojo

Added: 2025-03-27

Due Date: 2025-04-17

Description:

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2019-9875

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Vendor: Sitecore

Product: CMS and Experience Platform (XP)

Added: 2025-03-26

Due Date: 2025-04-16

Description:

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2019-9874

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Vendor: Sitecore

Product: CMS and Experience Platform (XP)

Added: 2025-03-26

Due Date: 2025-04-16

Description:

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-502

CVE-2025-30154

reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

Vendor: reviewdog

Product: action-setup GitHub Action

Added: 2025-03-24

Due Date: 2025-04-14

Description:

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

Required Action:

Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-506

CVE-2017-12637

SAP NetWeaver Directory Traversal Vulnerability

Vendor: SAP

Product: NetWeaver

Added: 2025-03-19

Due Date: 2025-04-09

Description:

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-22

CVE-2024-48248

NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

Vendor: NAKIVO

Product: Backup and Replication

Added: 2025-03-19

Due Date: 2025-04-09

Description:

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-36

CVE-2025-1316

Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Vendor: Edimax

Product: IC-7100 IP Camera

Added: 2025-03-19

Due Date: 2025-04-09

Description:

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

Required Action:

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CWEs:

CWE-78