Snapshot
March 8, 2025 - March 14, 2025
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2025-24985 | Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code with a physical attack. | HIGH | Microsoft | March 11, 2025 |
CVE-2025-24993 | Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that could allow an authorized attacker to execute code locally. | HIGH | Microsoft | March 11, 2025 |
CVE-2025-26633 | Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to execute code over a network. | HIGH | Microsoft | March 11, 2025 |
CVE-2025-24983 | Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | HIGH | Microsoft | March 11, 2025 |
CVE-2025-24991 | Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that could allow for information disclosure. | MEDIUM | Microsoft | March 11, 2025 |
CVE-2025-24984 | Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an authorized attacker to disclose information locally. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. | MEDIUM | Microsoft | March 11, 2025 |
CVE-2024-57968 | Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. | CRITICAL | Advantive | March 10, 2025 |
CVE-2024-13160 | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | CRITICAL | Ivanti | March 10, 2025 |
CVE-2024-13161 | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | CRITICAL | Ivanti | March 10, 2025 |
CVE-2024-13159 | Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. | CRITICAL | Ivanti | March 10, 2025 |
CVE-2025-25181 | Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. | MEDIUM | Advantive | March 10, 2025 |
Newswires |
||||
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2024-4577 (4) | In PHP versions 8.1. | CRITICAL | Php, Fedoraproject, Php Group |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
CVE-2024-13161 (2) | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update ... | CRITICAL | Ivanti |
CISA Known Exploited |
CVE-2024-13160 (2) | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update ... | CRITICAL | Ivanti |
CISA Known Exploited |
CVE-2024-13159 (2) | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update ... | CRITICAL | Ivanti |
CISA Known Exploited Remote Code Execution Public Exploits Available |
CVE-2012-1823 (1) | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script , does not properly handle q... | CRITICAL | Apple, Hp, Suse, Redhat, Php, Fedoraproject, Debian, Opensuse |
CISA Known Exploited Public Exploits Available |
CVE-2017-11882 (4) | Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microso... | HIGH | Microsoft |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2025-27840 (2) | Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 . | MEDIUM |
Public Exploits Available |
|
CVE-2024-43451 (2) | NTLM Hash Disclosure Spoofing Vulnerability | MEDIUM | Microsoft |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2024-12297 (2) | Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. | N/A |
Remote Code Execution |
CISA Known Exploited Vulnerabilities
CISA added 11 vulnerabilities to the known exploited vulnerabilities list.
Microsoft — Windows |
CVE-2025-24985 / Added: March 11, 2025 |
HIGH CVSS 7.80 |
Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code with a physical attack. |
Headlines |
Microsoft — Windows |
CVE-2025-24993 / Added: March 11, 2025 |
HIGH CVSS 7.80 |
Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that could allow an authorized attacker to execute code locally. |
Headlines |
Microsoft — Windows |
CVE-2025-26633 / Added: March 11, 2025 |
HIGH CVSS 7.00 |
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to execute code over a network. |
Headlines |
Microsoft — Windows |
CVE-2025-24983 / Added: March 11, 2025 |
HIGH CVSS 7.00 |
Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. |
Headlines |
Microsoft — Windows |
CVE-2025-24991 / Added: March 11, 2025 |
MEDIUM CVSS 5.50 |
Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that could allow for information disclosure. |
Headlines |
Microsoft — Windows |
CVE-2025-24984 / Added: March 11, 2025 |
MEDIUM CVSS 4.60 |
Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an authorized attacker to disclose information locally. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. |
Headlines |
Advantive — VeraCore |
CVE-2024-57968 / Added: March 10, 2025 |
CRITICAL CVSS 9.90 EPSS Score 0.23 EPSS Percentile 61.92 |
Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx. |
Headlines
|
Ivanti — Endpoint Manager (EPM) |
CVE-2024-13160 / Added: March 10, 2025 |
CRITICAL CVSS 9.80 EPSS Score 4.19 EPSS Percentile 92.31 |
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. |
Headlines
|
Ivanti — Endpoint Manager (EPM) |
CVE-2024-13161 / Added: March 10, 2025 |
CRITICAL CVSS 9.80 EPSS Score 4.19 EPSS Percentile 92.31 |
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. |
Headlines
|
Ivanti — Endpoint Manager (EPM) |
CVE-2024-13159 / Added: March 10, 2025 |
CRITICAL CVSS 9.80 EPSS Score 1.85 EPSS Percentile 88.36 |
Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information. |
Headlines
|
Advantive — VeraCore |
CVE-2025-25181 / Added: March 10, 2025 |
MEDIUM CVSS 5.80 EPSS Score 0.23 EPSS Percentile 61.92 |
Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter. |
Headlines
|
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2024-4577 |
CRITICAL CVSS 9.80 EPSS Score 95.18 EPSS Percentile 99.52 |
CISA Known Exploited Actively Exploited Remote Code Execution Used In Ransomware Public Exploits Available |
Published: June 9, 2024 |
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc. |
Vendors Impacted: Php, Fedoraproject, Php Group |
Products Impacted: Php, Fedora |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2024-13161 |
CRITICAL CVSS 9.80 EPSS Score 4.19 EPSS Percentile 92.31 |
CISA Known Exploited |
Published: Jan. 14, 2025 |
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
Vendor Impacted: Ivanti |
Product Impacted: Endpoint Manager (Epm) |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2024-13160 |
CRITICAL CVSS 9.80 EPSS Score 4.19 EPSS Percentile 92.31 |
CISA Known Exploited |
Published: Jan. 14, 2025 |
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
Vendor Impacted: Ivanti |
Product Impacted: Endpoint Manager (Epm) |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2024-13159 |
CRITICAL CVSS 9.80 EPSS Score 1.85 EPSS Percentile 88.36 |
CISA Known Exploited Remote Code Execution Public Exploits Available |
Published: Jan. 14, 2025 |
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
Vendor Impacted: Ivanti |
Product Impacted: Endpoint Manager (Epm) |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2012-1823 |
CRITICAL CVSS 9.80 EPSS Score 95.69 EPSS Percentile 99.59 |
CISA Known Exploited Public Exploits Available |
Published: May 11, 2012 |
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case. |
Vendors Impacted: Apple, Hp, Suse, Redhat, Php, Fedoraproject, Debian, Opensuse |
Products Impacted: Enterprise Linux Eus, Opensuse, Storage For Public Cloud, Enterprise Linux Workstation, Storage, Php, Mac Os X, Linux Enterprise Software Development Kit, Enterprise Linux Server Aus, Hp-Ux, Debian Linux, Gluster Storage Server For On-Premise, Fedora, Linux Enterprise Server, Enterprise Linux Desktop, Enterprise Linux Server, Application Stack |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2017-11882 |
HIGH CVSS 7.80 EPSS Score 97.42 EPSS Percentile 99.97 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Nov. 15, 2017 |
Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-11884. |
Vendor Impacted: Microsoft |
Product Impacted: Office |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2025-27840 |
MEDIUM CVSS 6.80 EPSS Score 0.05 EPSS Percentile 19.93 |
Public Exploits Available |
Published: March 8, 2025 |
Espressif ESP32 chips allow 29 hidden HCI commands, such as 0xFC02 (Write memory). |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2024-43451 |
MEDIUM CVSS 6.50 EPSS Score 0.94 EPSS Percentile 83.25 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Nov. 12, 2024 |
NTLM Hash Disclosure Spoofing Vulnerability |
Vendor Impacted: Microsoft |
Products Impacted: Windows 10 1607, Windows 10 22h2, Windows 11 22h2, Windows Server 2019, Windows 11 24h2, Windows 10 1507, Windows Server 2022, Windows 10 21h2, Windows, Windows Server 2025, Windows Server 2008, Windows Server 2012, Windows 10 1809, Windows Server 2022 23h2, Windows 11 23h2, Windows Server 2016 |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2024-12297 |
CVSS Not Assigned EPSS Score 0.04 EPSS Percentile 11.88 |
Remote Code Execution |
Published: Jan. 15, 2025 |
Moxa’s Ethernet switch is vulnerable to an authentication bypass because of flaws in its authorization mechanism. Although both client-side and back-end server verification are involved in the process, attackers can exploit weaknesses in its implementation. These vulnerabilities may enable brute-force attacks to guess valid credentials or MD5 collision attacks to forge authentication hashes, potentially compromising the security of the device. |
Quotes
|
Headlines |
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.