Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the current snapshot and ordered by catalog date and CASCA priority.

Evidence current through Aug 27, 2026, 6:09 PM UTC
CISA KEV catalog boundaryCatalog silence leaves exploitation status unassessed. Alternate serialization never counts as a second source.1,677 catalog members · showing 351–400
351
CVE-2025-1976CISA KEVSource-reported scopeEvidence supported

Broadcom Brocade Fabric OS Code Injection Vulnerability

Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.

BroadcomBrocade Fabric OS

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-28
Due
2025-05-19
Priority interval
65.967.4
Coverage
93%
352
CVE-2025-24054CISA KEVAssessments differAssessments differSource-reported scope

Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-17
Due
2025-05-08
Priority interval
76.084.5
Coverage
80%
353
CVE-2025-31200CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products Memory Corruption Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.

AppleMultiple Products

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-17
Due
2025-05-08
Priority interval
78.781.9
Coverage
93%
354
CVE-2025-31201CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products Arbitrary Read and Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.

AppleMultiple Products

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-17
Due
2025-05-08
Priority interval
77.280.1
Coverage
93%
355
CVE-2021-20035CISA KEVSource-reported scopeEvidence supported

SonicWall SMA100 Appliances OS Command Injection Vulnerability

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

SonicWallSMA100 Appliances

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-16
Due
2025-05-07
Priority interval
65.366.3
Coverage
99%
356
CVE-2024-53197CISA KEVSource-reported scopeEvidence supported

Linux Kernel Out-of-Bounds Access Vulnerability

Linux Kernel contains an out-of-bounds access vulnerability in the USB-audio driver that allows an attacker with physical access to the system to use a malicious USB device to potentially manipulate system memory, escalate privileges, or execute arbitrary code.

LinuxKernel

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-09
Due
2025-04-30
Priority interval
67.569.4
Coverage
97%
357
CVE-2024-53150CISA KEVSource-reported scopeEvidence supported

Linux Kernel Out-of-Bounds Read Vulnerability

Linux Kernel contains an out-of-bounds read vulnerability in the USB-audio driver that allows a local, privileged attacker to obtain potentially sensitive information.

LinuxKernel

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-09
Due
2025-04-30
Priority interval
64.366.2
Coverage
97%
358
CVE-2025-30406CISA KEVSource-reported scopeEvidence supported

Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability

Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploitation allows an attacker to forge ViewState payloads for server-side deserialization, allowing for remote code execution.

GladinetCentreStack

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-08
Due
2025-04-29
Priority interval
84.588.1
Coverage
93%
359
CVE-2025-29824CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-08
Due
2025-04-29
Priority interval
74.180.0
Coverage
93%
360
CVE-2025-31161CISA KEVKnown ransomwareSource-reported scopeEvidence supported

CrushFTP Authentication Bypass Vulnerability

CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromise.

CrushFTPCrushFTP

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-07
Due
2025-04-28
Priority interval
87.188.7
Coverage
95%
361
CVE-2025-22457CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

IvantiConnect Secure, Policy Secure, and ZTA Gateways

Required actionApply mitigations as set forth in the CISA instructions linked below.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-04
Due
2025-04-11
Priority interval
82.596.6
Coverage
85%
362
CVE-2025-24813CISA KEVSource-reported scopeEvidence supported

Apache Tomcat Path Equivalence Vulnerability

Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request. This vulnerability can be chained with CVE‐2026‐34486.

ApacheTomcat

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-04-01
Due
2025-04-22
Priority interval
89.891.1
Coverage
100%
363
CVE-2024-20439CISA KEVSource-reported scopeEvidence supported

Cisco Smart Licensing Utility Static Credential Vulnerability

Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.

CiscoSmart Licensing Utility

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-31
Due
2025-04-21
Priority interval
86.390.5
Coverage
88%
364
CVE-2025-2783CISA KEVSource-reported scopeEvidence supported

Google Chromium Mojo Sandbox Escape Vulnerability

Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being provided in unspecified circumstances. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium Mojo

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-27
Due
2025-04-17
Priority interval
69.471.0
Coverage
93%
365
CVE-2019-9874CISA KEVSource-reported scopeEvidence supported

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

SitecoreCMS and Experience Platform (XP)

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-26
Due
2025-04-16
Priority interval
86.387.6
Coverage
95%
366
CVE-2019-9875CISA KEVSource-reported scopeEvidence supported

Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability

Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.

SitecoreCMS and Experience Platform (XP)

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-26
Due
2025-04-16
Priority interval
72.173.7
Coverage
93%
367
CVE-2025-30154CISA KEVSource-reported scopeEvidence supported

reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability

reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.

reviewdogaction-setup GitHub Action

Required actionApply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-24
Due
2025-04-14
Priority interval
69.970.9
Coverage
98%
368
CVE-2024-48248CISA KEVSource-reported scopeEvidence supported

NAKIVO Backup and Replication Absolute Path Traversal Vulnerability

NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.

NAKIVOBackup and Replication

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-19
Due
2025-04-09
Priority interval
83.685.1
Coverage
93%
369
CVE-2025-1316CISA KEVSource-reported scopeEvidence supported

Edimax IC-7100 IP Camera OS Command Injection Vulnerability

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

EdimaxIC-7100 IP Camera

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-19
Due
2025-04-09
Priority interval
83.284.7
Coverage
93%
370
CVE-2017-12637CISA KEVSource-reported scopeEvidence supported

SAP NetWeaver Directory Traversal Vulnerability

SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files via a .. (dot dot) in the query string.

SAPNetWeaver

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-19
Due
2025-04-09
Priority interval
80.982.4
Coverage
93%
371
CVE-2025-30066CISA KEVSource-reported scopeEvidence supported

tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may include, but are not limited to, valid AWS access keys, GitHub personal access tokens (PATs), npm tokens, and private RSA keys.

tj-actionschanged-files GitHub Action

Required actionApply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-18
Due
2025-04-08
Priority interval
80.882.4
Coverage
93%
372
CVE-2025-24472CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability

Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.

FortinetFortiOS and FortiProxy

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-18
Due
2025-04-08
Priority interval
65.572.4
Coverage
85%
373
CVE-2025-24201CISA KEVSource-reported scopeEvidence supported

Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability

Apple iOS, iPadOS, macOS, and other Apple products contain an out-of-bounds write vulnerability in WebKit that may allow maliciously crafted web content to break out of Web Content sandbox. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

AppleMultiple Products

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-13
Due
2025-04-03
Priority interval
75.478.4
Coverage
95%
374
CVE-2025-21590CISA KEVSource-reported scopeEvidence supported

Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability

Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.

JuniperJunos OS

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-13
Due
2025-04-03
Priority interval
62.063.6
Coverage
100%
375
CVE-2025-26633CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-11
Due
2025-04-01
Priority interval
68.582.2
Coverage
85%
376
CVE-2025-24985CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-11
Due
2025-04-01
Priority interval
70.676.5
Coverage
92%
377
CVE-2025-24993CISA KEVSource-reported scopeEvidence supported

Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-11
Due
2025-04-01
Priority interval
69.675.5
Coverage
93%
378
CVE-2025-24983CISA KEVSource-reported scopeEvidence supported

Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-11
Due
2025-04-01
Priority interval
64.870.4
Coverage
92%
379
CVE-2025-24991CISA KEVSource-reported scopeEvidence supported

Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-11
Due
2025-04-01
Priority interval
63.769.6
Coverage
93%
380
CVE-2025-24984CISA KEVSource-reported scopeEvidence supported

Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-11
Due
2025-04-01
Priority interval
61.367.1
Coverage
92%
381
CVE-2024-13159CISA KEVAssessments differAssessments differSource-reported scope

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

IvantiEndpoint Manager (EPM)

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-10
Due
2025-03-31
Priority interval
81.488.7
Coverage
86%
382
CVE-2024-13160CISA KEVAssessments differAssessments differSource-reported scope

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

IvantiEndpoint Manager (EPM)

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-10
Due
2025-03-31
Priority interval
80.587.8
Coverage
86%
383
CVE-2024-13161CISA KEVAssessments differAssessments differSource-reported scope

Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

IvantiEndpoint Manager (EPM)

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-10
Due
2025-03-31
Priority interval
80.487.7
Coverage
86%
384
CVE-2024-57968CISA KEVAssessments differAssessments differSource-reported scope

Advantive VeraCore Unrestricted File Upload Vulnerability

Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.

AdvantiveVeraCore

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-10
Due
2025-03-31
Priority interval
76.080.3
Coverage
80%
385
CVE-2025-25181CISA KEVAssessments differAssessments differSource-reported scope

Advantive VeraCore SQL Injection Vulnerability

Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.

AdvantiveVeraCore

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-10
Due
2025-03-31
Priority interval
72.278.0
Coverage
80%
386
CVE-2025-22225CISA KEVKnown ransomwareSource-reported scopeEvidence supported

VMware ESXi Arbitrary Write Vulnerability

VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.

VMwareESXi

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-04
Due
2025-03-25
Priority interval
62.576.4
Coverage
85%
387
CVE-2025-22224CISA KEVAssessments differAssessments differSource-reported scope

VMware ESXi and Workstation TOCTOU Race Condition Vulnerability

VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local administrative privileges on a virtual machine to execute code as the virtual machine's VMX process running on the host.

VMwareESXi and Workstation

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-04
Due
2025-03-25
Priority interval
68.074.1
Coverage
86%
388
CVE-2025-22226CISA KEVAssessments differAssessments differSource-reported scope

VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability

VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to a virtual machine to leak memory from the vmx process.

VMwareESXi, Workstation, and Fusion

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-04
Due
2025-03-25
Priority interval
63.069.4
Coverage
86%
389
CVE-2024-50302CISA KEVSource-reported scopeEvidence supported

Linux Kernel Use of Uninitialized Resource Vulnerability

The Linux kernel contains a use of uninitialized resource vulnerability that allows an attacker to leak kernel memory via a specially crafted HID report.

LinuxKernel

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-04
Due
2025-03-25
Priority interval
62.164.9
Coverage
96%
390
CVE-2024-4885CISA KEVSource-reported scopeEvidence supported

Progress WhatsUp Gold Path Traversal Vulnerability

Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.

ProgressWhatsUp Gold

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-03
Due
2025-03-24
Priority interval
87.189.7
Coverage
90%
391
CVE-2022-43939CISA KEVAssessments differAssessments differSource-reported scope

Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability

Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.

Hitachi VantaraPentaho Business Analytics (BA) Server

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-03
Due
2025-03-24
Priority interval
83.487.9
Coverage
83%
392
CVE-2022-43769CISA KEVAssessments differAssessments differSource-reported scope

Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability

Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.

Hitachi VantaraPentaho Business Analytics (BA) Server

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-03
Due
2025-03-24
Priority interval
80.486.0
Coverage
83%
393
CVE-2018-8639CISA KEVKnown ransomwareSource-reported scopeEvidence supported

Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

MicrosoftWindows

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-03
Due
2025-03-24
Priority interval
75.881.6
Coverage
94%
394
CVE-2023-20118CISA KEVAssessments differAssessments differSource-reported scope

Cisco Small Business RV Series Routers Command Injection Vulnerability

Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.

CiscoSmall Business RV Series Routers

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-03-03
Due
2025-03-24
Priority interval
76.379.0
Coverage
85%
395
CVE-2023-34192CISA KEVSource-reported scopeEvidence supported

Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoSaveDraft function.

SynacorZimbra Collaboration Suite (ZCS)

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-02-25
Due
2025-03-18
Priority interval
82.784.3
Coverage
100%
396
CVE-2024-49035CISA KEVAssessments differAssessments differSource-reported scope

Microsoft Partner Center Improper Access Control Vulnerability

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.

MicrosoftPartner Center

Required actionApply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-02-25
Due
2025-03-18
Priority interval
66.771.0
Coverage
80%
397
CVE-2017-3066CISA KEVSource-reported scopeEvidence supported

Adobe ColdFusion Deserialization Vulnerability

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

AdobeColdFusion

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-02-24
Due
2025-03-17
Priority interval
86.287.7
Coverage
100%
398
CVE-2024-20953CISA KEVSource-reported scopeEvidence supported

Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.

OracleAgile Product Lifecycle Management (PLM)

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-02-24
Due
2025-03-17
Priority interval
68.671.2
Coverage
90%
399
CVE-2025-24989CISA KEVAssessments differAssessments differSource-reported scope

Microsoft Power Pages Improper Access Control Vulnerability

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.

MicrosoftPower Pages

Required actionApply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Assessments differfactor_c_cvss

Eligible assertions materially conflict and remain visible side by side.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
Resolve conflict
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-02-21
Due
2025-03-14
Priority interval
65.771.2
Coverage
80%
400
CVE-2025-23209CISA KEVSource-reported scopeEvidence supported

Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.

Craft CMSCraft CMS

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Evidence reason details
Evidence supportedfactor_a_kev

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_b_epss

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Resolution
None
Evidence supportedfactor_c_cvss

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Resolution
None
Source-reported scopefactor_d_breadth

The source assertion is retained, but its canonical identity is unresolved.

Revision
casca-factor-d-obligations-v1
Cutoff
Resolution
Resolve identity
Added
2025-02-20
Due
2025-03-13
Priority interval
72.073.8
Coverage
98%