Report Name: pt_trend_cve_combined2025Generated: 2025-07-17 13:18:30
| Product Name | Prevalence | U | C | H | M | L | A | Comment |
|---|---|---|---|---|---|---|---|---|
| Apache HTTP Server | 0.9 | 1 | 1 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | ||||
| Windows NTLM | 0.9 | 1 | 1 | A suite of security protocols to authenticate users' identity and protect the integrity and confidentiality of their activity | ||||
| Windows SMB Client | 0.9 | 1 | 1 | Windows component | ||||
| Microsoft DWM Core Library | 0.8 | 1 | 1 | Windows component | ||||
| Microsoft Management Console | 0.8 | 1 | 1 | Microsoft Management Console (MMC) is a component of Microsoft Windows that provides system administrators and advanced users an interface for configuring and monitoring the system | ||||
| Microsoft Windows File Explorer | 0.8 | 1 | 1 | Windows component | ||||
| Windows Ancillary Function Driver for WinSock | 0.8 | 1 | 1 | Windows component | ||||
| Windows Cloud Files Mini Filter Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows Common Log File System Driver | 0.8 | 3 | 3 | Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs | ||||
| Windows Fast FAT File System Driver | 0.8 | 1 | 1 | Windows component | ||||
| Windows Hyper-V NT Kernel Integration VSP | 0.8 | 3 | 3 | Windows component | ||||
| Windows Lightweight Directory Access Protocol (LDAP) | 0.8 | 1 | 1 | Windows component | ||||
| Windows NTFS | 0.8 | 1 | 1 | The default file system of the Windows NT family | ||||
| Windows OLE | 0.8 | 1 | 1 | Windows component | ||||
| Windows Process Activation | 0.8 | 1 | 1 | Windows component | ||||
| Windows Storage | 0.8 | 1 | 1 | Windows component | ||||
| Windows Win32 Kernel Subsystem | 0.8 | 1 | 1 | Windows component | ||||
| Apache Tomcat | 0.7 | 1 | 1 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | ||||
| ESXi | 0.7 | 1 | 2 | 3 | VMware ESXi (formerly ESX) is an enterprise-class, type-1 hypervisor developed by VMware for deploying and serving virtual computers | |||
| Kubernetes | 0.7 | 1 | 1 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | ||||
| MDaemon Email Server | 0.6 | 1 | 1 | MDaemon Email Server is an email server application with groupware functions for Microsoft Windows. MDaemon supports multiple client-side protocols, including IMAP, POP3, SMTP/MSA, webmail, CalDAV, CardDAV, and optionally ActiveSync for mobile clients and Outlook, and its Connector for Outlook add-on. | ||||
| Roundcube | 0.6 | 1 | 1 | Roundcube is a web-based IMAP email client | ||||
| 7-Zip | 0.5 | 1 | 1 | 2 | 7-Zip is a free and open-source file archiver, a utility used to place groups of files within compressed containers known as "archives" | |||
| FortiOS | 0.5 | 1 | 1 | FortiOS is Fortinet's operating system used in their hardware, such as the Fortigate firewall and switches | ||||
| Internet Shortcut Files | 0.5 | 1 | 1 | Internet Shortcut Files | ||||
| Microsoft Configuration Manager | 0.5 | 1 | 1 | Microsoft Configuration Manager | ||||
| PAN-OS | 0.5 | 1 | 1 | PAN-OS is the software that runs all Palo Alto Networks next-generation firewalls | ||||
| CommuniGate Pro | 0.4 | 1 | 1 | CommuniGate Pro is a highly scalable carrier grade unified communications server, as well as a development platform | ||||
| Erlang/OTP | 0.4 | 1 | 1 | Erlang/OTP is a set of libraries for the Erlang programming language | ||||
| Zimbra Collaboration | 0.3 | 1 | 1 | Zimbra Collaboration is a collaborative software suite that includes an email server and a web client |
| Vulnerability Type | Criticality | U | C | H | M | L | A |
|---|---|---|---|---|---|---|---|
| Remote Code Execution | 1.0 | 10 | 4 | 1 | 15 | ||
| Authentication Bypass | 0.98 | 2 | 2 | ||||
| Security Feature Bypass | 0.9 | 1 | 1 | ||||
| Elevation of Privilege | 0.85 | 8 | 5 | 13 | |||
| Information Disclosure | 0.83 | 1 | 1 | ||||
| Cross Site Scripting | 0.8 | 2 | 2 | ||||
| Memory Corruption | 0.5 | 1 | 1 | ||||
| Spoofing | 0.4 | 2 | 2 |
| Source | U | C | H | M | L | A |
|---|
1.
Remote Code Execution - Apache HTTP Server (CVE-2024-38475) - Urgent [971]
Description: Improper escaping of output in mod_rewrite in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:GHOSTTROOPS:TOP, Vulners:PublicExploit:GitHub:P0IN7S:CVE-2024-38475, Vulners:PublicExploit:GitHub:MRMTWOJ:APACHE-VULNERABILITY-TESTING, Vulners:PublicExploit:GitHub:HKTALENT:TOP, Vulners:PublicExploit:GitHub:SOLTANALI0:CVE-2024-38475, Vulners:PublicExploit:GitHub:ABREWER251:CVE-2024-38475_SONICBOOM_APACHE_URL_TRAVERSAL_POC, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | Apache HTTP Server is a free and open-source web server that delivers web content through the internet | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 1.0 | 10 | EPSS Probability is 0.9355, EPSS Percentile is 0.99826 |
2.
Remote Code Execution - Apache Tomcat (CVE-2025-24813) - Urgent [950]
Description: Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache
3.
Remote Code Execution - Roundcube (CVE-2025-49113) - Urgent [933]
Description:
4.
Remote Code Execution - Windows Fast FAT File System Driver (CVE-2025-24985) - Urgent [919]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:www.vicarius.io, Vulners:PublicExploit:GitHub:AIRBUS-CERT:CVE-2025-24985, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.8 | 10 | EPSS Probability is 0.00925, EPSS Percentile is 0.75045 |
5.
Elevation of Privilege - Windows Hyper-V NT Kernel Integration VSP (CVE-2025-21333) - Urgent [916]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:MUKESH-BLEND:CVE-2025-21333-POC, Vulners:PublicExploit:GitHub:GHOSTTROOPS:TOP, Vulners:PublicExploit:GitHub:SERABILEM:CVE-2025-21333-POC, Vulners:PublicExploit:GitHub:160102:CVE-2025-21333-POC, Vulners:PublicExploit:GitHub:HKTALENT:TOP, Vulners:PublicExploit:GitHub:B1ACK4SH:BLACKASH-CVE-2025-21333, Vulners:PublicExploit:GitHub:MRALE98:CVE-2025-21333-POC, BDU:PublicExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 1.0 | 10 | EPSS Probability is 0.56696, EPSS Percentile is 0.97988 |
6.
Remote Code Execution - Microsoft Configuration Manager (CVE-2024-43468) - Urgent [916]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on BDU website | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SYNACKTIV:CVE-2024-43468, Vulners:PublicExploit:GitHub:NIKALLASS:CVE-2024-43468_MTLS_GO, Vulners:PublicExploit:GitHub:TADASH10:DETAILED-ANALYSIS-AND-MITIGATION-STRATEGIES-FOR-CVE-2024-38124-AND-CVE-2024-43468, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Microsoft Configuration Manager | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 1.0 | 10 | EPSS Probability is 0.80028, EPSS Percentile is 0.99048 |
7.
Authentication Bypass - FortiOS (CVE-2024-55591) - Urgent [913]
Description: An
8.
Elevation of Privilege - Microsoft DWM Core Library (CVE-2025-30400) - Urgent [904]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ENCRYPTER15:CVE-2025-30400 website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.03697, EPSS Percentile is 0.87449 |
9.
Elevation of Privilege - Windows Common Log File System Driver (CVE-2025-29824) - Urgent [904]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:www.vicarius.io, Vulners:PublicExploit:GitHub:ENCRYPTER15:CVE-2025-29824, BDU:PublicExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.0269, EPSS Percentile is 0.85238 |
10.
Authentication Bypass - PAN-OS (CVE-2025-0108) - Urgent [901]
Description: An authentication bypass in the Palo Alto Networks
11.
Security Feature Bypass - Microsoft Management Console (CVE-2025-26633) - Urgent [901]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:www.vicarius.io, Vulners:PublicExploit:GitHub:SANDSONCOSTA:CVE-2025-26633, BDU:PublicExploit websites | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Microsoft Management Console (MMC) is a component of Microsoft Windows that provides system administrators and advanced users an interface for configuring and monitoring the system | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.07394, EPSS Percentile is 0.91274 |
12.
Remote Code Execution - Erlang/OTP (CVE-2025-32433) - Urgent [899]
Description:
13.
Remote Code Execution - Internet Shortcut Files (CVE-2025-33053) - Urgent [892]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:THETORJANCAPTAIN:CVE-2025-33053-CHECKER-POC, Vulners:PublicExploit:GitHub:DEVBUIHIEU:CVE-2025-33053-PROOF-OF-CONCEPT, Vulners:PublicExploit:GitHub:KRA1T0:CVE-2025-33053-WEBDAV-RCE-POC-AND-C2-CONCEPT, Vulners:PublicExploit:EDB-ID:52334, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Internet Shortcut Files | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.18114, EPSS Percentile is 0.94866 |
14.
Remote Code Execution - 7-Zip (CVE-2025-0411) - Urgent [880]
Description:
15.
Cross Site Scripting - MDaemon Email Server (CVE-2024-11182) - Urgent [850]
Description: An XSS issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on ESET: Operation RoundPress website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | MDaemon Email Server is an email server application with groupware functions for Microsoft Windows. MDaemon supports multiple client-side protocols, including IMAP, POP3, SMTP/MSA, webmail, CalDAV, CardDAV, and optionally ActiveSync for mobile clients and Outlook, and its Connector for Outlook add-on. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 1.0 | 10 | EPSS Probability is 0.32256, EPSS Percentile is 0.9663 |
16.
Spoofing - Windows NTLM (CVE-2025-24054) - Urgent [840]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:www.vicarius.io, Vulners:PublicExploit:GitHub:YURI08LOVEELAINA:CVE-2025-24054_POC, Vulners:PublicExploit:GitHub:HELIDEM:CVE-2025-24054_CVE-2025-24071-POC, Vulners:PublicExploit:GitHub:PSWALIA2U:CVE-2025-24071_POC, Vulners:PublicExploit:GitHub:MARCEJR117:CVE-2025-24071_POC, Vulners:PublicExploit:GitHub:0X6RSS:CVE-2025-24071_POC, Vulners:PublicExploit:GitHub:CLEMENTNJERU:CVE-2025-24054-POC, Vulners:PublicExploit:GitHub:HELIDEM:CVE-2025-24054-POC, Vulners:PublicExploit:EDB-ID:52280, BDU:PublicExploit websites | |
| 0.4 | 15 | Spoofing | |
| 0.9 | 14 | A suite of security protocols to authenticate users' identity and protect the integrity and confidentiality of their activity | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to Microsoft data source | |
| 1.0 | 10 | EPSS Probability is 0.38746, EPSS Percentile is 0.97095 |
17.
Remote Code Execution - Windows NTFS (CVE-2025-24993) - Urgent [829]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | The default file system of the Windows NT family | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.03226, EPSS Percentile is 0.86545 |
18.
Remote Code Execution - ESXi (CVE-2025-22224) - Urgent [825]
Description: VMware
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | VMware ESXi (formerly ESX) is an enterprise-class, type-1 hypervisor developed by VMware for deploying and serving virtual computers | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 1.0 | 10 | EPSS Probability is 0.37103, EPSS Percentile is 0.96981 |
19.
Spoofing - Microsoft Windows File Explorer (CVE-2025-24071) - Urgent [823]
Description:
20.
Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2025-21418) - Urgent [802]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.11464, EPSS Percentile is 0.9327 |
21.
Elevation of Privilege - Windows Common Log File System Driver (CVE-2025-32701) - Urgent [802]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.04192, EPSS Percentile is 0.88231 |
22.
Elevation of Privilege - Windows Common Log File System Driver (CVE-2025-32706) - Urgent [802]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Common Log File System is a general-purpose logging subsystem that is accessible to both kernel-mode as well as user-mode applications for building high-performance transaction logs | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.12062, EPSS Percentile is 0.93461 |
23.
Elevation of Privilege - Windows Hyper-V NT Kernel Integration VSP (CVE-2025-21334) - Urgent [802]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.04579, EPSS Percentile is 0.8874 |
24.
Elevation of Privilege - Windows Hyper-V NT Kernel Integration VSP (CVE-2025-21335) - Urgent [802]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, CISA object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.05766, EPSS Percentile is 0.90056 |
25.
Cross Site Scripting - Zimbra Collaboration (CVE-2024-27443) - Urgent [800]
Description: An issue was discovered in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, NVD:CISAKEV, BDU websites | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on ESET: Operation RoundPress website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.3 | 14 | Zimbra Collaboration is a collaborative software suite that includes an email server and a web client | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 1.0 | 10 | EPSS Probability is 0.22962, EPSS Percentile is 0.95637 |
26.
Elevation of Privilege - Windows Storage (CVE-2025-21391) - Critical [791]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Microsoft data source | |
| 0.9 | 10 | EPSS Probability is 0.04197, EPSS Percentile is 0.88237 |
27.
Elevation of Privilege - Windows Win32 Kernel Subsystem (CVE-2025-24983) - Critical [779]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, Microsoft, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploits is mentioned on Microsoft:PrivateExploit:Functional, BDU:PrivateExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Microsoft data source | |
| 0.8 | 10 | EPSS Probability is 0.01465, EPSS Percentile is 0.80023 |
28.
Information Disclosure - ESXi (CVE-2025-22226) - Critical [758]
Description: VMware
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | VMware ESXi (formerly ESX) is an enterprise-class, type-1 hypervisor developed by VMware for deploying and serving virtual computers | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.0362, EPSS Percentile is 0.87316 |
29.
Remote Code Execution - Windows Lightweight Directory Access Protocol (LDAP) (CVE-2024-49112) - Critical [752]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:TNKR:POC_MONITOR, Vulners:PublicExploit:GitHub:BO0L3AN:CVE-2024-49112-POC, GitHub:SafeBreach-Labs:CVE-2024-49113 websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 1.0 | 10 | EPSS Probability is 0.8668, EPSS Percentile is 0.99372 |
30.
Remote Code Execution - Windows OLE (CVE-2025-21298) - Critical [752]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:GHOSTTROOPS:TOP, Vulners:PublicExploit:GitHub:HKTALENT:TOP, Vulners:PublicExploit:GitHub:DENYNINGBOW:RTF-CTF-CVE-2025-21298, Vulners:PublicExploit:GitHub:MR-BIG-LEACH:CVE-2025-21298, Vulners:PublicExploit:GitHub:YNWARCS:CVE-2025-21298, BDU:PublicExploit, GitHub:ynwarcs:CVE-2025-21298 websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Windows component | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to Microsoft data source | |
| 1.0 | 10 | EPSS Probability is 0.70558, EPSS Percentile is 0.98599 |
31.
Remote Code Execution - Kubernetes (CVE-2025-1974) - Critical [735]
Description: A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary
32.
Memory Corruption - ESXi (CVE-2025-22225) - Critical [723]
Description: VMware
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on Vulners (AttackerKB object, cisa_kev object), AttackerKB, NVD:CISAKEV, BDU websites | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | VMware ESXi (formerly ESX) is an enterprise-class, type-1 hypervisor developed by VMware for deploying and serving virtual computers | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.04911, EPSS Percentile is 0.89144 |
33.
Elevation of Privilege - Windows Cloud Files Mini Filter Driver (CVE-2024-30085) - Critical [701]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ADAMKADABAN:CVE-2024-30085, Vulners:PublicExploit:GitHub:MURDOK1982:EXPLOIT-POC-PARA-CVE-2024-30085, Vulners:PublicExploit:MSF:EXPLOIT-WINDOWS-LOCAL-CVE_2024_30085_CLOUD_FILES-, BDU:PublicExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 1.0 | 10 | EPSS Probability is 0.56198, EPSS Percentile is 0.97968 |
34.
Remote Code Execution - CommuniGate Pro (BDU:2025-01331) - Critical [679]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 1.0 | 18 | Exploitation in the wild is mentioned on CyberOK_News:89 website | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | CommuniGate Pro is a highly scalable carrier grade unified communications server, as well as a development platform | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to BDU data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
35.
Elevation of Privilege - Windows SMB Client (CVE-2025-33073) - Critical [670]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:JOAOZIXX:CVE-2025-33073, Vulners:PublicExploit:GitHub:GHOSTTROOPS:TOP, Vulners:PublicExploit:GitHub:HKTALENT:TOP, Vulners:PublicExploit:GitHub:MVERSCHU:CVE-2025-33073, Vulners:PublicExploit:GitHub:OBSCURA-CERT:CVE-2025-33073, Vulners:PublicExploit:EDB-ID:52330, BDU:PublicExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | Windows component | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to Microsoft data source | |
| 0.5 | 10 | EPSS Probability is 0.00326, EPSS Percentile is 0.54978 |
36.
Elevation of Privilege - Windows Process Activation (CVE-2025-21204) - Critical [666]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:MMOTTI:RESET-INETPUB, BDU:PublicExploit, CYBERDOM: Abusing the Windows Update Stack to Gain SYSTEM Access (CVE-2025-21204) websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Windows component | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Microsoft data source | |
| 0.7 | 10 | EPSS Probability is 0.00597, EPSS Percentile is 0.68424 |
37.
Remote Code Execution - 7-Zip (BDU:2025-01793) - High [535]
Description: The vulnerability in the Mark-of-the-Web protection mechanism of the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Trick or Threat website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | 7-Zip is a free and open-source file archiver, a utility used to place groups of files within compressed containers known as "archives" | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to BDU data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |