Known Exploited Vulnerabilities (KEV)

ID Title Severity CVSS EPSS Source Updated
cve-2025-30567 WordPress WP01 plugin <= 2.6.2 - Arbitrary File Download Vulnerability HIGH 7.5 N/A cvelistv5 2026-06-17
cve-2025-30406 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability HIGH N/A N/A cvelistv5 2025-04-08
cve-2025-30400 Microsoft Windows DWM Core Library Use-After-Free Vulnerability HIGH N/A N/A cvelistv5 2025-05-13
cve-2025-30349 CVE-2025-30349 HIGH 7.2 N/A cvelistv5
cve-2025-30259 The WhatsApp cloud service before late 2024 did not block certain crafted PDF content that can defeat a sandbox protection mechanism and consequently allow remote access to messaging applications by third parties, as exploited in the wild in 2024 for installation of Android malware associated with BIGPRETZEL. LOW 3.5 N/A cvelistv5 2026-06-17
cve-2025-30220 GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling CRITICAL 9.9 N/A cvelistv5 2026-06-17
cve-2025-30154 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability HIGH N/A N/A cvelistv5 2025-03-24
cve-2025-30066 tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability HIGH 8.6 N/A cvelistv5 2025-03-18
cve-2025-29927 nextjs: Authorization Bypass in Next.js Middleware CRITICAL 9.1 N/A cvelistv5 2026-07-11
cve-2025-29063 CVE-2025-29063 CRITICAL 9.8 N/A cvelistv5
cve-2025-28367 mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey. MEDIUM 6.5 N/A cvelistv5 2026-06-17
cve-2025-2825 CVE-2025-2825 HIGH N/A N/A cvelistv5
cve-2025-28137 The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. CRITICAL 9.8 N/A cvelistv5 2026-06-17
cve-2025-28036 TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through the NoticeUrl parameter. CRITICAL 9.8 N/A cvelistv5 2026-06-17
cve-2025-27920 Srimax Output Messenger Directory Traversal Vulnerability HIGH N/A N/A cvelistv5 2025-05-19
cve-2025-27915 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability HIGH N/A N/A cvelistv5 2025-10-07
cve-2025-2783 Google Chromium Mojo Sandbox Escape Vulnerability HIGH N/A N/A cvelistv5 2025-03-27
cve-2025-2777 CVE-2025-2777 CRITICAL 9.3 N/A cvelistv5
cve-2025-2776 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability CRITICAL 9.3 N/A cvelistv5 2025-07-22
cve-2025-2775 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability CRITICAL 9.3 N/A cvelistv5 2025-07-22
cve-2025-27505 GeoServer Missing Authorization on REST API Index MEDIUM 5.3 N/A cvelistv5 2026-06-17
cve-2025-2747 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability HIGH N/A N/A cvelistv5 2025-10-20
cve-2025-2746 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability HIGH N/A N/A cvelistv5 2025-10-20
cve-2025-27363 FreeType Out-of-Bounds Write Vulnerability HIGH N/A N/A cvelistv5 2025-05-06
cve-2025-27222 CVE-2025-27222 HIGH 8.6 N/A cvelistv5
cve-2025-27112 SUSE CVE CVE-2025-27112 MEDIUM 6.5 N/A cvelistv5 2026-08-22
cve-2025-27038 Qualcomm Multiple Chipsets Use-After-Free Vulnerability HIGH N/A N/A cvelistv5 2025-06-03
cve-2025-26793 The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with default credentials (username freedom, password viscount). The administrator is not prompted to change these credentials on initial configuration, and changing the credentials requires many steps. Attackers can use the credentials over the Internet via mesh.webadmin.MESHAdminServlet to gain access to dozens of Canadian and U.S. apartment buildings and obtain building residents' PII. NOTE: the Supplier's perspective is that the "vulnerable systems are not following manufacturers' recommendations to change the default password." CRITICAL 9.3 N/A cvelistv5 2026-06-17
cve-2025-26633 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability HIGH 7.0 N/A cvelistv5 2025-03-11
cve-2025-26319 CVE-2025-26319 CRITICAL 9.8 N/A cvelistv5