SonicWall Releases Patches in Actively Exploited Privilege Escalation Vulnerability | Medium | CVE-2025-40602 | 12/18/2025 | 1.0 |
| Apple iOS & iPadOS Patch 0-Days Vulnerabilities, Exploited in Targeted Attacks | Critical | CVE-2025-43529, CVE-2025-14174, CVE-2025-46285 and more | 12/15/2025 | 1.0 |
| Attackers to Bypass FortiCloud-SSO Authentication;Patches Released for FortiOS, FortiProxy, FortiWeb | Critical | CVE-2025-59718, CVE-2025-59719 | 12-10-25 | 1.0 |
| SAP Dec 2025 Security Patch Released, Critical RCE Fixed & DoS Vulnerabilities | Critical | CVE-2025-42880, CVE-2025-55754, CVE-2025-42928, CVE-2025-42878 & 10 more CVEs | 12-09-25 | 1.0 |
| Critical Vulnerabilities Identified in React Server Components & Next.js | Critical | CVE-2025-55182, CVE-2025-66478 | 12-05-25 | 1.0 |
| Cisco Splunk Enterprise Security Patch Fixed Windows Permissions Misconfiguration | High | CVE-2025-20386, CVE-2025-20387 | 12-05-25 | 1.0 |
| Android Security Patch December 2025 Fixed 100+ Vulnerabilities Including Zero-Days | Critical | CVE-2025-48631, CVE-2025-48633, CVE-2025-48572 & 104 more CVEs | 12-03-25 | 1.0 |
Security Advisory
Chrome 143 Update Released, Fixes RCE & Multiple High Severity Vulnerabilities | High | CVE-2025-13630, CVE-2025-13631, CVE-2025-13632, CVE-2025-13633 & 9 other CVEs. | 12-03-25 | 1.0 |
| Urgent OpenVPN Security Patch to Stop Remote Denial of Service Attacks | Critical | CVE-2025-12106, CVE-2025-13086 | 12-02-25 | 1.0 |
| NVIDIA DGX Spark Security Update Fixed 14 Vulnerabilities | Critical | CVE-2025-33187, CVE-2025-33188, CVE-2025-33189 & 11 more CVEs | 11/28/2025 | 1.0 |
Security Advisory
Apache Syncope Patched Security Vulnerability that Affected Multiple Versions of the Identity & Access Management Platform | High | CVE-2025-65998 | 11/27/2025 | 1.0 |
| Shai-Hulud’s ‘Second Coming’ npm Malware Infects Popular Developer Packages | High | NA | 11/26/2025 | 1.0 |
| Critical Fluent Bit Vulnerabilities Allow RCE & Cloud Infrastructure at Risk | Critical | CVE-2025-12969, CVE-2025-12970, CVE-2025-12972, CVE-2025-12977, CVE-2025-12978 | 11/25/2025 | 1.0 |
| Microsoft Patched Critical Azure Bastion Elevation of Privilege Vulnerability | Critical | CVE-2025-49752 | 11/24/2025 | 1.0 |
| SonicWall SSLVPN Vulnerability Allows Remote Attackers to Crash Firewalls | High | CVE-2025-40601 | 11/21/2025 | 1.0 |
| Chrome V8 Type Confusion Vulnerability Actively Exploited In The Wild | High | CVE-2025-13223, CVE-2025-13224 | 11/18/2025 | 1.0 |
| Zoho Analytics On-Premise Critical SQL Injection Vulnerability Allows Attackers to Takeover Data | Critical | CVE-2025-8324 | 11/14/2025 | 1.0 |
| Mozilla Firefox Releases 145 Security Updates, 16 High-Severity Vulnerabilities across multiple Firefox versions & Platforms | High | CVE-2025-13012, CVE-2025-13016 , CVE-2025-13021 and others | 11/13/2025 | 1.0 |
| Gladinet Triofox Patched Critical Unauthenticated Remote Access Vulnerability | Critical | CVE-2025-12480 | 11-12-25 | 1.0 |
| Microsoft November Updates- Fixes 63 Vulnerabilities,1 Zero-Day Exploits ; Patch Now | Critical | CVE-2025-62215, CVE-2025- 62199 and other 61 issues | 11-12-25 | 1.0 |
Security Advisory
Amazon Workspace Client for Linux Token Vulnerability Fixed in Version 2025.0 | High | CVE-2025-12779 | 11-07-25 | 1.0 |
| Chrome Latest Update Fixes Multiple High-Severity Security Flaws | High | CVE-2025-12725, CVE-2025-12726, CVE-2025-12727, CVE-2025-12728, CVE-2025-12729 | 11-06-25 | 1.0 |
| Critical React Native CLI Vulnerability Enables OS Command Injection | Critical | CVE-2025-11953 | 11-05-25 | 1.0 |
| Apple Releases iOS & iPadOS 26.1 Update, Fixed Multiple Security Vulnerabilities | High | CVE-2025-43438, CVE-2025-43429, CVE-2025-43442, CVE-2025-43455, CVE-2025-43398 & others | 11-04-25 | 1.0 |
| Critical Brash Vulnerability: Blink Engine Flaw Breaks Chromium Browsers | High | NA | 10/31/2025 | 1.0 |
| Critical Apache Tomcat Vulnerabilities Enable RCE | Critical | CVE-2025-55754, CVE-2025-55752 | 10/29/2025 | 1.0 |
| High-severity path traversal vulnerability was identified in Docker Compose | High | CVE-2025-62725 | 10/29/2025 | 1.0 |
| Copilot Studio SupplyChain Attack Steals OAuth Tokens via CoPhishing | High | NA | 10/28/2025 | 1.0 |
| Microsoft Teams Access Token Vulnerability Allows Attack Vector for Data Exfiltration | High | NA | 10/27/2025 | 1.0 |
Blogs Security Advisory
Samsung Galaxy S25 Zero-Day Exploit Exposes Camera & Location | High | NA | 10/27/2025 | 1.0 |
| TARmageddon Exploitable Tar Extraction Flaw Exposes Systems to Privilege Escalation | High | CVE-2025-62518 | 10/27/2025 | 1.0 |
| TP-Link Security Update, Omada Gateway Exploits Fixed in October Release | Critical | CVE-2025-6541, CVE-2025-6542, CVE-2025-7850, CVE-2025-7851 | 10/22/2025 | 1.0 |
Security Advisory
WatchGuard Patched Critical Vulnerability, Allowing RCE in Firebox Appliances | Critical | CVE-2025-9242 | 10/22/2025 | 1.0 |
| Advanced eBPF Rootkit LinkPro Evade Detection in Linux Systems via Magic TCP Packets | High | NA | 10/18/2025 | 1.0 |
| Fortinet Released Security Update’s; Patched Multiple High & Medium Severity Vulnerabilities | High | CVE-2025-49201, CVE-2025-58325, CVE-2025-57740, CVE-2025-57741 & others | 10/16/2025 | 1.0 |
| Ivanti Endpoint Manager Vulnerabilities Expose Systems to RCE, SQL & Privilege Escalation Risks | High | CVE-2025-11622, CVE-2025-9713 & CVEs for SQL | 10/15/2025 | 1.0 |
| Microsoft October Patch Fixes 175 Vulnerabilities, 6 Zero-Days & Critical Exploits | Critical | CVE-2025-24990, CVE-2025-59230 and others | 10/15/2025 | 1.0 |
| Elastic Patched Critical Jinjava Template Injection in Elastic Cloud Enterprise(ECE) | Critical | CVE-2025-37729 | 10/14/2025 | 1.0 |
| Elastic Releases Critical Security Updates for Kibana & Elasticsearch | High | CVE-2025-25009, CVE-2025-25017, CVE-2025-25018, CVE-2025-37727, CVE-2025-37728 | 10-09-25 | 1.0 |
| CrowdStrike Releases Security Updates for Falcon Sensor Windows Vulnerabilitie | Medium | CVE-2025-42701, CVE-2025-42706 | 10-09-25 | 1.0 |
| Critical Lua Sandbox Escape Flaw in Redis Allows Remote Code Execution (RCE) | Critical | CVE-2025-49844 | 10-08-25 | 1.0 |
| Google Chrome Patched High-Severity Memory Vulnerabilities | High | CVE-2025-11458, CVE-2025-11460, CVE-2025-11211 | 10-08-25 | 1.0 |
| Critical Oracle EBS 0-Day Hit by Clop Ransomware; Oracle Released Emergency Patch | Critical | CVE-2025-61882 | 10-06-25 | 1.0 |
| CISA Warns Critical Cisco Firewall Vulnerabilities Under Active Exploitation | Critical | CVE-2025-20333, CVE-2025-20362 | 9/26/2025 | 1.0 |
| Zero-Click ShadowLeak Vulnerability in ChatGPT Agent Exposes Sensitive Data via Hidden Email Prompts | High | NA | 9/19/2025 | 1.0 |
| Radware Uncovers Server Side Attack Targeting ChatGPT Known as Shadowleak | High | NA | 9/19/2025 | 1.0 |
| Chrome Security Update Fixed Active Zero-Day Exploit & Multiple High-Severity Vulnerabilities | High | CVE-2025-10585, CVE-2025-10500, CVE-2025-10501, CVE-2025-10502 | 9/18/2025 | 1.0 |
| Jenkins Security Patch Fixed HTTP/2 DoS and Permission Issues | High | CVE-2025-5115, CVE-2025-59474, CVE-2025-59475, CVE-2025-59476 | 9/18/2025 | 1.0 |
| Spring Security & Framework Authorization Bypass Vulnerabilities Patched | Medium | CVE-2025-41248, CVE-2025-41249 | 9/17/2025 | 1.0 |
| Shai-Hulud NPM Supply Chain Attack Expands to 470+ Packages | High | NA | 9/17/2025 | 1.0 |
| VoidProxy PhaaS Uses MFA Bypass, Hijacking Google and Microsoft Logins | High | NA | 9/16/2025 | 1.0 |
| Angular SSR Vulnerability Allows Cross-Request Data Exposure | High | CVE-2025-59052 | 09-12-25 | 1.0 |
| Microsoft Releases September 2025 Security Updates: 86 Fixes, 2 Zero-Day Vulnerabilities | High | CVE-2025-55234, CVE-2024-21907 | 09-10-25 | 1.0 |
| Patch Now: Critical Unauthorized Property Modification Vulnerability in Spring Cloud Gateway WebFlux | Critical | CVE-2025-41243 | 09-09-25 | 1.0 |
| Critical WhatsApp Zero-Day Vulnerability Allows Remote Code Execution | Medium | CVE-2025-55177 | 09-05-25 | 1.0 |
| Chrome Update Released, Fixes RCE and Multiple Vulnerabilities | High | CVE-2025-9864, CVE-2025-9865, CVE-2025-9866, CVE-2025-9867 | 09-05-25 | 1.0 |
| Fake Government & Banking Apps Used to Spread Android Malware | High | NA | 09-04-25 | 1.0 |
| MediaTek Patches Critical Modem Vulnerabilities Affecting Millions of Devices | High | CVE-2025-20708, CVE-2025-20703, CVE-2025-20704, CVE-2025-20705, CVE-2025-20706, CVE-2025-20707 | 09-03-25 | 1.0 |
| Critical Chrome Use-After-Free Vulnerability in ANGLE Graphics Library | High | CVE-2025-9478 | 8/29/2025 | 1.0 |
| Multiple Critical Vulnerabilities in Citrix NetScaler ADC/Gateway, One Actively Exploited in Wild | Critical | CVE-2025-7775, CVE-2025-7776, CVE-2025-8424 | 8/28/2025 | 1.0 |
| Docker Desktop Vulnerability Allows Full Host Compromise via Exposed API | Critical | CVE-2025-9074 | 8/24/2025 | 1.0 |
| Apple Patches Zero-Day Vulnerability Exploited in Targeted Attacks (CVE-2025-43300) | High | CVE-2025-43300 | 8/22/2025 | 1.0 |
| WhatsApp Privacy Advisory: Protect Your Conversations | High | N/A | 8/20/2025 | 1.0 |
| PostgreSQL High-Severity RCE Flaws in pg_dump Utilities Allow Remote Code Execution | High | CVE-2025-8715, CVE-2025-8714, CVE-2025-8713 | 8/19/2025 | 1.0 |
| Microsoft IIS Web Deploy RCE Vulnerability Allows Authenticated Remote Code Execution | High | CVE-2025-53772 | 8/18/2025 | 1.0 |
| Microsoft Patches 119 Vulnerabilities in August Patch Tuesday; Kerberos Zero‑Day Publicly Disclosed | Critical | CVE-2025-53779 | 8/13/2025 | 1.0 |
| 7-Zip Security Flaw Allows Malicious File Writes and Potential Exploits | Low | CVE-2025-55188 | 08-12-25 | 1.0 |
| WinRAR Zero-Day Path Traversal Flaw Actively Exploited to Code Execution | High | CVE-2025-8088 | 08-11-25 | 1.0 |
| Zero-Day Exploitation in SonicWall Targeted by Akira Ransomware | Critical | N/A | 08-06-25 | 1.0 |
| Patch Now! Claude Code Vulnerabilities Allow Unauthorized Command Execution, CVEs Affect AI Security Foundations | High | CVE-2025-54794, CVE-2025-54795 | 08-05-25 | 1.0 |
| Gemini CLI Vulnerability Enables Silent Execution of Malicious Commands on Developer Systems | Critical | N/A | 08-01-25 | 1.0 |
| Patch Now! Critical Command Injection in GitHub Action tj-actions/branch-names Affects 5,000+ Repos | Critical | CVE-2025-54416 | 7/29/2025 | 1.0 |
| Pre-Auth Remote Code Execution Flaws Patched in Sophos Firewall | Critical | CVE-2025-6704, CVE-2025-7624 | 7/23/2025 | 1.0 |
| Critical Remote Code Execution in Nokia WaveSuite NOC | Critical | CVE-2025-24936, CVE-2025-24938 | 7/22/2025 | 1.0 |
| Critical Zero-Day Vulnerabilities in VMware Exploited at Pwn2Own 2025 – Patch Immediately | Critical | CVE-2025-41236, CVE-2025-41237, CVE-2025-41238, CVE-2025-41239 | 7/18/2025 | 1.0 |
| ToolShell Zero-Day Exploits in Microsoft SharePoint Enable Full Remote Takeover | Critical | CVE-2025-34067 | 7/18/2025 | 1.0 |
| Google Addresses Actively Exploited Zero-Day Vulnerability CVE-2025-6558 in Chrome | High | CVE-2025-6558 | 7/17/2025 | 1.0 |
| CVE-2025-34067: Critical RCE in HikCentral Puts Global Surveillance at Risk, PoC Available | Critical | CVE-2025-34067 | 7/17/2025 | 1.0 |
| Mercedes, VW, Skoda Cars at Risk from Critical PerfektBlue Bluetooth Vulnerabilities | High | CVE-2024-45431, CVE-2024-45432, CVE-2024-45433, CVE-2024-45434, | 7/16/2025 | 1.0 |
| SEO Poisoning Campaign Targets IT Admins with Weaponized PuTTY and WinSCP | High | N/A | 7/15/2025 | 1.0 |
| Phishing for Gemini: Invisible Prompts Turn AI Summaries into Attack Vectors | High | N/A | 7/14/2025 | 1.0 |
| Critical Flaws Expose Schneider DCE to Remote Exploits – Patch Now | Critical | CVE-2025-50121, CVE-2025-50122, CVE-2025-50123, CVE-2025-50125 | 07-11-25 | 1.0 |
| CitrixBleed 2: Critical CVE-2025-5777 Vulnerability Under Active Exploitation with Public PoC Available | Critical | CVE-2025-5777 | 07-09-25 | 1.0 |
| Grafana Fixes Critical Chromium Vulnerabilities, Including Active Zero-Day Exploit | High | CVE-2025-6554, CVE-2025-5959, CVE-2025-6191
CVE-2025-6192 | 07-09-25 | 1.0 |
| Microsoft Plug 140 Vulnerabilities in July Patch Tuesday; SQL Server Zero-Day Disclosed | High | N/A | 07-09-25 | 1.0 |
| Linux Local Privilege Escalation via udisksd and libblockdev (CVE-2025-6019) PoC released | High | CVE-2025-6019 | 07-07-25 | 1.0 |
| 12-Year-Old Sudo Vulnerability and Chroot Flaw Enable Privilege Escalation | Critical | CVE-2025-32463, CVE-2025-32462 | 07-04-25 | 1.0 |
| Google Chrome Zero-Day Vulnerability (CVE-2025-6554) Actively Exploited – Patch Now | Critical | CVE-2025-6554 | 07-01-25 | 1.0 |
| Critical Unauthenticated RCE Vulnerabilities in Cisco ISE and ISE-PIC | Critical | CVE-2025-20281, CVE-2025-20282 | 6/27/2025 | 1.0 |
| Citrix NetScaler ADC/Gateway Vulnerability Exploited in the Wild (CVE-2025-6543) | Critical | CVE-2025-6543 | 6/26/2025 | 1.0 |
| Privilege Escalation in Notepad++ v8.8.1 Installer via Binary Planting with Public PoC Available | High | CVE-2025-49144 | 6/24/2025 | 1.0 |
| Privilege Escalation Vulnerability in AI Engine WordPress Plugin, Allows Subscriber-Level Account Takeover | High | CVE-2025-5071 | 6/20/2025 | 1.0 |
| Apache Tomcat Vulnerabilities Expose Systems to DoS and Authentication Bypass | High | N/A | 6/18/2025 | 1.0 |
| Google Chrome Zero-Day CVE-2025-2783 Exploited in APT Group TaxOff Campaigns | High | CVE-2025-2783 | 6/18/2025 | 1.0 |
| Veeam Backup Patched Critical Vulnerabilities Enabling RCE & Privilege Escalation | Critical | CVE-2025-23121, CVE-2025-24286, CVE-2025-24287 | 6/18/2025 | 1.0 |
| Microsoft June 2025 Patch Tuesday – 67 Vulnerabilities Fixed Including 2 Zero-Days | High | N/A | 06-12-25 | 1.0 |
| Critical 0-Day RCE Vulnerability in Fortinet Products (CVE-2025-32756) Actively Exploited | Critical | CVE-2025-32756 | 06-10-25 | 1.0 |
| POC Released for Critical RCE Vulnerability in AWS Amplify Codegen-UI | Critical | CVE-2025-4318 | 06-09-25 | 1.0 |
| Critical Credential Reuse Vulnerability in Cisco ISE Cloud Deployments | Critical | CVE-2025-20286 | 06-06-25 | 1.0 |
| Reflected XSS Vulnerability in Splunk Enterprise & Cloud Platform | Medium | CVE-2025-48866 | 06-05-25 | 1.0 |
| Critical Zero-Day Vulnerabilities in Qualcomm Adreno GPU Drivers Actively Exploited | High | CVE-2025-31324, CVE-2025-42999 | 06-04-25 | 1.0 |
| Critical Vulnerabilities Patched in IBM QRadar Suite and Cloud Pak for Security | Critical | CVE-2025-25022, CVE-2025-2502, CVE-2025-25020, CVE-2025-25019, CVE-2025-1334 | 06-04-25 | 1.0 |
| High Risk DoS Vulnerability in ModSecurity WAF | High | CVE-2025-20297 | 06-04-25 | 1.0 |
| Google Chrome Patches Actively Exploited Zero-Day Vulnerability | High | CVE-2025-5419 | 06-03-25 | 1.0 |
| BadSuccessor Vulnerability in Windows Server 2025 Enables Domain Admin Privilege Escalation | Medium | N/A | 5/28/2025 | 1.0 |
| Remote Command Execution Risk in Legacy D-Link Routers Due to Hardcoded Telnet Credentials | Medium | CVE-2025-46176 | 5/27/2025 | 1.0 |
| Linux Kernel Exploitation in ksmbd (CVE-2025-37899) Discovered with AI Assistance | High | CVE-2025-37899 | 5/23/2025 | 1.0 |
| Cisco ISE and UIC Security Flaws Allow DoS and Privilege Escalation | High | CVE-2025-20152, CVE-2025-20113, CVE-2025-20114 | 5/22/2025 | 1.0 |
| Critical Privilege Escalation Vulnerability in Motors WordPress Theme | Critical | CVE-2025-4322 | 5/21/2025 | 1.0 |
| Critical Firefox 0-Day Vulnerabilities Exploited at Pwn2Own 2025 – Immediate Update Required | High | CVE-2025-4918, CVE-2025-4919 | 5/20/2025 | 1.0 |
| Zero-Day Threat in Chrome’s Loader Component (CVE-2025-4664) – CISA Flags Urgent Risk | Medium | CVE-2025-4664 | 5/14/2025 | 1.0 |
| Microsoft May 2025 Patch Tuesday Released; Fixed 83 Vulnerabilities, Including 5 Zero-Days | High | N/A | 5/13/2025 | 1.0 |
| Critical SAP NetWeaver Vulnerabilities Addressed in May 2025 Patch – Immediate Action Required | High | CVE-2025-31324, CVE-2025-42999 | 5/13/2025 | 1.0 |
| FBI Warns End-of-Life Routers Exploited in Active Botnet and Proxy Campaigns | High | N/A | 05-11-25 | 1.0 |
| OpenCTI Web-Hook Flaw Enables Full System Compromise | Critical | CVE-2025-24977 | 05-06-25 | 1.0 |
| Apache Parquet Java Vulnerability Enables Remote Code Execution via Avro Schema | High | CVE-2025-46762 | 05-05-25 | 1.0 |
| Tesla Model 3 VCSEC Vulnerability Allows Remote Code Execution via TPMS Exploit | High | CVE-2025-2082 | 05-02-25 | 1.0 |
| High-Severity Linux Kernel Flaw Exposes Systems to Root-Level Attacks | High | CVE-2025-21756 | 4/30/2025 | 1.0 |
| Critical SAP NetWeaver Zero-day Vulnerability Exploited in the Wild | Critical | CVE-2025-31324 | 4/29/2025 | 1.0 |
| Windows Update Stack Privilege Escalation Vulnerability (CVE-2025-21204) – PoC Released | High | CVE-2025-21204 | 4/23/2025 | 1.0 |
| Windows 11 DLL Flaws Open Doors to Privilege Escalation! | High | CVE-2025-24994, CVE-2025-24076 | 4/21/2025 | 1.0 |
| Critical Session Management Vulnerability in Apache Roller | Critical | CVE-2025-24859 | 4/15/2025 | 1.0 |
| Dell Releases Patches for Multiple PowerScale OneFS Security Vulnerabilities | Critical | CVE-2025-27690, CVE-2025- 26330, CVE-2025-22471 | 4/13/2025 | 1.0 |
| Critical Flaw in FortiSwitch of Fortinet Allows Attackers to Change Admin Password | Critical | CVE-2024-48887 | 04-10-25 | 1.0 |
| Spoofing Vulnerability in WhatsApp Desktop for Windows | Medium | CVE-2025-30401 | 04-09-25 | 1.0 |
| April Zero-Day Threats Addressed in Microsoft’s Patch Tuesday | High | N/A | 04-09-25 | 1.0 |
| WordPress Ultimate CSV Importer Flaws Put 20,000+ Sites at Risk | High | CVE-2025-2008, CVE- 2025-2007 | 04-03-25 | 1.0 |
| 3 Zero-Day Vulnerabilities backported & fixed in Apple Devices | High | CVE-2025-24201, CVE-2025-24085, and CVE-2025-24200. | 04-02-25 | 1.0 |
| Windows Zero-Day Exploit NTLM Hash Disclosure via Malicious Files | Critical | Zero-Day | 3/28/2025 | 1.0 |
| Critical Chrome Vulnerability (CVE-2025-2783) Exploited in Cyber-Espionage Campaign | High | CVE-2025-2783 | 3/28/2025 | 1.0 |
| Update Google Chrome to Fix Critical Remote Code Execution Vulnerability in Lens | High | CVE-2025-2476 | 3/25/2025 | 1.0 |
| Critical NGINX Ingress Vulnerabilities Expose Kubernetes Clusters to Compromise | Critical | N/A | 3/25/2025 | 1.0 |
| WordPress Age Gate Plugin Critical Vulnerability (CVE-2025-2505) Affects Over 40,000 Websites | Critical | CVE-2025-2505 | 3/24/2025 | 1.0 |
| New Exploit Allows Remote Code Execution in Apache Tomcat | Critical | CVE-2025-24813 | 3/20/2025 | 1.0 |
| Apache NiFi Security Flaw Exposes MongoDB Credentials | Medium | CVE-2025-27017 | 3/17/2025 | 1.0 |
| Multiple High-Severity Vulnerabilities Patched in Zoom | High | CVE-2025-27440, CVE-2025-27439, CVE-2025-0151, CVE-2025-0150, CVE-2025-0149 | 3/14/2025 | 1.0 |
| Zero-Day Threats Addressed in Microsoft’s March 2025 Patch Tuesday | Critical | -- | 3/13/2025 | 1.0 |
| High-Severity RCE Vulnerability in WinDbg (CVE-2025-24043) | High | CVE-2025-24043 | 03-12-25 | 1.0 |
| PoC Released for High-Severity Linux Kernel UVC Driver Vulnerability | High | CVE-2024-53104 | 03-11-25 | 1.0 |
| Critical VMware Vulnerabilities Exploited in the Wild – Patch Immediately | Critical | CVE-2025-22224, CVE-2025-22225, CVE-2025-22226 | 03-07-25 | 1.0 |
| Critical Security Flaw in Kibana Requires Immediate Attention | Critical | CVE-2025-25012 | 03-07-25 | 1.0 |
| Critical Vulnerabilities in IBM Storage: Authentication Bypass and Code Execution Risks | Critical | CVE-2025-0159, CVE-2025-0160 | 03-06-25 | 1.0 |
| Decade-Old Threat: CVE-2018-8639 Still Poses Risks to Unpatched Windows | High | CVE-2018-8639 | 03-05-25 | 1.0 |
| Wazuh Server Vulnerability (CVE-2025-24016) Exposes Systems to RCE Attacks | Critical | CVE-2025-24016 | 03-04-25 | 1.0 |
| High-Severity DoS Vulnerability in Cisco NX-OS Software | High | CVE-2025-20111 | 2/28/2025 | 1.0 |
| Critical WordPress Security Flaw in Everest Forms Plugin | Critical | CVE-2025-1128 | 2/27/2025 | 1.0 |
| Exploitable Command Injection in F5 BIG-IP (CVE-2025-20029) | High | CVE-2025-20029 | 2/24/2025 | 1.0 |
| Palo Alto Firewall Vulnerabilities Under Active Exploitation | High | CVE-2025-0108 | 2/20/2025 | 1.0 |
| Authentication Bypass Vulnerability in FortiOS & FortiProxy | Critical | CVE-2025-24472 | 2/13/2025 | 1.0 |
| Apple’s USB Restricted Mode Exploited in Targeted Attacks | High | -- | 02-12-25 | 1.0 |
| Microsoft Updates Patch Tuesday for Feb 2025; Address 67 Vulnerabilities, Includes 2 Exploited Zero-Days | High | -- | 02-12-25 | 1.0 |
| 7Zip Mark-Of-The-Web Vulnerability | High | CVE-2025-0411 | 02-10-25 | 1.0 |
| Active Exploitation of Microsoft Outlook RCE Vulnerability (CVE-2024-21413) | Critical | CVE-2024-21413 | 02-07-25 | 1.0 |
| Zero-Day Vulnerability in Microsoft Sysinternals Tools | High | -- | 02-05-25 | 1.0 |
| macOS Security at Risk: PoC Exploit for CVE-2025-24118 Kernel Flaw | Critical | CVE-2025-24118 | 02-03-25 | 1.0 |
| High-Severity SMB Server Flaws (CVE-2024-56626 & CVE-2024-56627) in Linux Kernel | High | CVE-2024-56626, CVE-2024-56627 | 1/29/2025 | 1.0 |
| Apple Patched Actively Exploited Zero-Day Vulnerability | High | CVE-2025-24085 | 1/29/2025 | 1.0 |
| Privilege Escalation Vulnerability Exposes Cisco Meeting Management to Attacks | Critical | CVE-2025-20156 | 1/24/2025 | 1.0 |
| Critical Authentication Bypass Vulnerability in Fortinet Products Under Active Exploitation | Critical | CVE-2024-55591 | 1/23/2025 | 1.0 |
| Critical Zero-Day Vulnerability in Windows (CVE-2024-49138): PoC Released, Exploited in the Wild | High | CVE-2024-49138 | 1/20/2025 | 1.0 |
| Privilege Escalation Vulnerability in ComboBlocks Plugin Affects Thousands of Sites | Critical | CVE-2024-9636 | 1/17/2025 | 1.0 |
| Critical Security Updates: Microsoft Jan 2025 Patch Tuesday Fixes 8 Zero-Days & 159 Vulnerabilities | Critical | -- | 1/16/2025 | 1.0 |
| Important Security Alert: SonicWall Issues Patch for SSL-VPN Vulnerabilities | High | CVE-2024-53704 | 1/15/2025 | 1.0 |
| Banshee Stealer: A Growing Threat to macOS Users | High | -- | 1/15/2025 | 1.0 |
| GitLab Releases Patch to Fix Critical and High-Severity Vulnerabilities | High | -- | 1/13/2025 | 1.0 |
| Ivanti Connect Secure VPN Actively Being Exploited in the Wild | High | CVE-2025-0282, CVE-2025-0283 | 01-10-25 | 1.0 |
| Race Condition Vulnerability in OpenSSH (CVE-2024-6387): PoC Exploit Released | High | CVE-2024-6387 | 01-09-25 | 1.0 |
| Critical Windows Privilege Escalation Vulnerability with Public Exploit | High | CVE-2024-43641 | 01-07-25 | 1.0 |
| Exploit Proof-of-Concept Released for LDAP CVE-2024-49113 | Critical | CVE-2024-49113 | 01-06-25 | 1.0 |
| Denial of Service Vulnerability in DNS Security Feature of Palo Alto Networks PAN-OS | High | CVE-2024-3393 | 01-03-25 | 1.0 |
| Critical Apache Tomcat Vulnerabilities Allow RCE & DoS | Critical | CVE-2024-50379, CVE-2024-54677 | 12/21/2024 | 1.0 |
| Security Advisory Cleo Releases Patch for Critical Vulnerabilities Exploited in the Wild | Critical | CVE-2024-55956, CVE-2024-50623 | 12/18/2024 | 1.0 |
| Critical Flaw in WordPress Hunk Companion Plugin Enables Unauthorized Plugin Installation | Critical | CVE-2024-11972 | 12/17/2024 | 1.0 |
| Security Advisory Zero-Day Vulnerability in Windows Exposes NTLM Credentials | Critical | Not yet assigned | 12/13/2024 | 1.0 |
| Microsoft December 2024 Patch Tuesday: Critical Fixes for Zero-Day and Remote Code Execution | High | -- | 12-12-24 | 1.0 |
| Advisory on MUT-8694: Threat Actors Exploiting Developer Trust in Open-Source Libraries | High | -- | 12-10-24 | 1.0 |
| RCE and File Deletion Vulnerabilities in Veeam Service Provider Console | Critical | CVE-2024-42448, CVE-2024-42449 | 12-05-24 | 1.0 |
| Security Update for NVIDIA Base Command & Bright Cluster Managers | Medium | CVE-2024-0139 | 11/29/2024 | 1.0 |
| Re-release of November 2024 Exchange Server Security Updates | High | CVE-2024-49040 | 11/27/2024 | 1.0 |
| November 2024 Microsoft Patches: Addressing Zero-Day Exploits and High-Priority Vulnerabilities | High | -- | 11/13/2024 | 1.0 |
| Palo Alto Account Takeover Vulnerability Actively Exploited | Critical | CVE-2024-5910 | 11-08-24 | 1.0 |
| Critical Remote Code Execution Vulnerability in VMware vCenter Server (CVE-2024-38812) | Critical | CVE-2024-38812, CVE-2024-38813 | 10/23/2024 | 1.0 |
| Threat Campaign Targeting WordPress Sites with Malicious Plugins | Critical | -- | 10/22/2024 | 1.0 |
| Veeam Vulnerability (CVE-2024-40711) Exploited by Ransomware | Critical | CVE-2024-40711 | 10/17/2024 | 1.0 |
| Critical Fortinet Vulnerability Exploiting in Wild | Critical | CVE-2024-23113 | 10/16/2024 | 1.0 |
| Security Advisory Microsoft’s October Security Patches Mitigate Remote Code Execution & Spoofing Risk | Critical | -- | 10-10-24 | 1.0 |
| Zimbra Remote Code Execution Vulnerability (CVE-2024-45519) | Critical | CVE-2024-45519 | 10-03-24 | 1.0 |
| Widespread of the Necro Trojan Targeting Android Users | Critical | -- | 9/26/2024 | 1.0 |
| Critical RCE Vulnerability Patched in Ivanti Endpoint Manager | Critical | CVE-2024-29847 | 9/18/2024 | 1.0 |