VulnSea

Tagged “kev”

CVEs tagged kev, newest first.

338 CVEsRSS

CVE-2025-59374Critical· 9.8CISA KEV0day
9mo ago

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting…

"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting…

▾ Hadalasus · live_updateEPSS 1.2%via NVD
CVE-2025-43529High· 8.8CISA KEV0dayPoC
9mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing malici…

▾ AbyssalApple · SafariEPSS 8.8%via CVEORG
CVE-2025-43520Medium· 5.5CISA KEVPoC
9mo ago

A memory corruption issue was addressed with improved memory handling

A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, …

▾ MidnightApple · iOS and iPadOSEPSS 0.43%via CVEORG
CVE-2025-14174High· 8.8CISA KEV0dayPoC
9mo ago

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page

Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

▾ AbyssalGoogle · ChromeEPSS 22%via CVEORG
CVE-2025-62221High· 7.8CISA KEV0dayPoC
9mo ago

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

▾ Abyssalmicrosoft · windows_10_1809EPSS 2.5%via NVD
CVE-2025-34291High· 8.8CISA KEVPoC
9mo ago

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution

Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a …

▾ Abyssallangflow · langflowEPSS 93%via NVD
CVE-2025-55182Critical· 10.0CISA KEVPoC
9mo ago

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-serve…

▾ Hadalfacebook · reactEPSS 100%via NVD
CVE-2025-62593CriticalCISA KEVPoC
10mo ago

Ray is an AI compute engine

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…

▾ Hadalray · rayEPSS 62%via NVD
CVE-2025-13223High· 8.8CISA KEVPoC
10mo ago

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 5.0%via NVD
CVE-2023-43000High· 8.8CISA KEVPoC
10mo ago

A use-after-free issue was addressed with improved memory management

A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to …

▾ Abyssalapple · safariEPSS 3.9%via NVD
CVE-2025-39964High· 7.8CISA KEVPoC
11mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable…

▾ Abyssallinux · linux_kernelEPSS 1.00%via NVD
CVE-2025-61884High· 7.5CISA KEVPoC
11mo ago

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …

▾ Abyssaloracle · configuratorEPSS 96%via NVD
CVE-2025-11371High· 7.5CISA KEVPoC
11mo ago

Gladinet CentreStack and TrioFox Local File Inclusion Flaw

In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been obser…

▾ AbyssalGladinet · CentreStack and TrioFoxEPSS 92%via CVEORG
CVE-2025-61882Critical· 9.8CISA KEV0dayPoC
11mo ago

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration)

Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: BI Publisher Integration). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated…

▾ Hadaloracle · concurrent_processingEPSS 100%via NVD
CVE-2025-20352High· 7.7CISA KEVPoC
1y ago

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low privileges could cause a denial of serv…

▾ Abyssalcisco · ios_xe_sd-wanEPSS 39%via NVD
CVE-2025-10585Critical· 9.8CISA KEV0dayPoC
1y ago

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

▾ Hadalgoogle · chromeEPSS 5.4%via NVD
CVE-2025-10035Critical· 10.0CISA KEVPoC
1y ago

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

▾ Hadalfortra · goanywhere_managed_file_transferEPSS 100%via NVD
CVE-2025-9242Critical· 9.8CISA KEVPoC
1y ago

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office V…

▾ Hadalwatchguard · firewareEPSS 91%via NVD
CVE-2025-39682Critical· 9.8CISA KEVPoC⚖ disputed
1y ago

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA re…

▾ Hadallinux · linux_kernelEPSS 2.9%via NVD
CVE-2025-57819Critical· 9.8CISA KEV0dayPoC
1y ago

FreePBX is an open-source web-based graphical user interface

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrar…

▾ Hadalsangoma · freepbxEPSS 85%via NVD
CVE-2025-8875High· 7.8CISA KEV0dayPoC
1y ago

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

▾ Abyssaln-able · n-centralEPSS 1.9%via NVD
CVE-2025-8088High· 8.8CISA KEVPoC
1y ago

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepano…

▾ Abyssalrarlab · winrarEPSS 94%via NVD
CVE-2025-31277High· 8.8CISA KEVPoC
1y ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory…

▾ Abyssalapple · safariEPSS 1.6%via NVD
CVE-2025-38352High· 7.8CISA KEVPoC
1y ago

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: fix race between handle_posix_cpu_timers() and posix_cpu_timer_del() If an exiting non-autoreaping task has already passed exit_notify() and calls ha…

▾ Abyssallinux · linux_kernelEPSS 1.3%via NVD
CVE-2025-53770Critical· 9.8CISA KEV0dayPoC
1y ago

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing…

▾ Hadalmicrosoft · sharepoint_serverEPSS 100%via NVD
CVE-2025-6558High· 8.8CISA KEVPoC
1y ago

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

▾ Abyssalgoogle · chromeEPSS 9.6%via NVD
CVE-2025-48384High· 8.0CISA KEVPoC
1y ago

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals

Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. When reading a config value, Git strips any trailing carriage return a…

▾ Abyssalgit-scm · gitEPSS 4.1%via NVD
CVE-2025-49706Medium· 6.5CISA KEVPoC
1y ago

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

▾ Midnightmicrosoft · sharepoint_enterprise_serverEPSS 99%via NVD
CVE-2025-5777High· 7.5CISA KEVPoC
1y ago

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

▾ Abyssalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2025-43200Medium· 4.2CISA KEV0day
1y ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.…

▾ Midnightapple · ipadosEPSS 1.2%via NVD
CVEs tagged “kev” — page 4 · VulnSea