Skip to content
VulniPulse

Complete feed

Exploited / KEV

Known exploitation or KEV-listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8F5 Exploited CISA KEV

Critical [CVE-2025-53521] When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVE-2025-53521
BIG-IP
Oct 15, 2025
HighIvanti Exploited

High October 2025 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Neurons for MDM. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: In addition, Ivanti has issued a Security Advisory for Ivanti Endpoint Manager, which provides mitigation options for vulnerabilities disclosed October 7, 2025. It is important for customers to know:

EPMM / MobileIronNeuronsEndpoint Manager
Oct 14, 2025
HighIvanti Exploited

High September 2025 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. At the core, we believe that responsible transparency helps protect our customers. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager (EPM) and Ivanti Connect Secure, Policy Secure, ZTA Gateways and Neurons for Secure Access. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: - Ivanti Connect Secure, Policy Secure, ZTNA and nSA

Connect Secure (VPN)Policy SecureNeuronsEndpoint Manager
Sep 9, 2025
Critical9.2NetScaler Exploited CISA KEV

Critical [CVE-2025-7775 +2] Critical security update announced for NetScaler Gateway and NetScaler

Cloud Software Group released builds on August 26, 2025, to address three security vulnerabilities. NetScaler Gateway & NetScaler is affected by CVE-2025-7775, which has a CVSS score of 9.2. CVE-2025-7776 impacts NetScaler Gateway (CVSS 8.8), CVE-2025-8424 impacts NetScaler (CVSS 8.7). Affected products named by the advisory: NetScaler ADC; NetScaler Console.

CVE-2025-7775CVE-2025-7776CVE-2025-8424
NetScaler ADCNetScaler GatewayNetScaler Console
Aug 26, 2025
HighIvanti Exploited

High August 2025 Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. At the core, we believe that responsible transparency helps protect our customers. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Avalanche, Ivanti Virtual Application Delivery Control (vADC) (previously known as vTM) and Ivanti Connect Secure, Policy Secure, ZTA Gateways and Neurons for Secure Access. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories:

Connect Secure (VPN)Policy SecureNeurons
Aug 12, 2025
Critical9.8MS Server Exploited CISA KEV

Critical [CVE-2025-53770] Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2025-53770
SharePoint Server
Jul 20, 2025
UnratedNetScaler Exploited CISA KEV

Advisory [CVE-2025-5777] Evaluating NetScaler logs for indicators of attempted exploitation of CVE-2025-5777

In our recent update to our announcement of CVE 2025-5777, we noted that on July 10, 2025, CISA added CVE-2025-5777 to its Known Exploited Vulnerabilities Catalog. To help customers assess their security posture, we’ve provided additional guidance below. Affected product named by the advisory: Gateway.

CVE-2025-5777
NetScaler Gateway
Jul 16, 2025
HighIvanti Exploited

High July Security Update

Ivanti releases standard security patches on the second Tuesday of every month. Our vulnerability management program is central to our commitment to maintaining secure products. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. We believe that responsible transparency helps protect our customers, and that CVE disclosures are an essential and effective tool to communicate software vulnerabilities. The purpose of assigning a CVE is to provide a beacon to security teams and signal the need for urgent updates. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Connect Secure and Policy Secure, Ivanti EPM, and Ivanti EPMM. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories:

Connect Secure (VPN)Policy SecureEPMM / MobileIronEndpoint Manager
Jul 8, 2025
Medium6.5MS Server Exploited CISA KEV

Medium [CVE-2025-49706] Microsoft SharePoint Server Spoofing Vulnerability

Improper authentication in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. Affected products named by the advisory: Microsoft SharePoint Enterprise Server 2016; Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.

CVE-2025-49706
SharePoint Server
Jul 8, 2025
HighIvanti Exploited

High June Security Update

Ivanti releases standard security patches on the second Tuesday of every month. It is our philosophy that responsible transparency helps protect our customers. CVE disclosures are an essential and effective tool for communicating software vulnerabilities and necessary actions to customers. A CVE serves as a beacon to security teams and signals the need for urgent updates. Today, Ivanti is disclosing vulnerabilities in Ivanti Workspace Control. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste into your preferred RSS reader / functionality in your email program.

Unclassified
Jun 10, 2025
HighIvanti Exploited

High May Security Update

Ivanti releases standard security patches on the second Tuesday of every month. For many of our customers, the predictable schedule facilitates better planning and management of IT resources, allowing them to allocate time and personnel efficiently for the timely updates. Today, Ivanti is disclosing vulnerabilities in Ivanti ITSM (on-premises only), Cloud Security Application (CSA) and Neurons for MDM. It is important for customers to know: - We have no evidence of any of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisories: Our Support team is always available to help customers and partners should they have any questions. Cases can be logged via the Success portal (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste into your preferred RSS reader / functionality in your email program.

Neurons
May 13, 2025
CriticalCommvault Exploited CISA KEV

Critical [CVE-2025-34028] Vulnerability in Commvault Command Center Installation

Vulnerability in Commvault Command Center Installation

CVE-2025-34028
Web Server / Command Center
May 7, 2025
HighCommvault Exploited CISA KEV

High [CVE-2025-3928] Critical Webserver Vulnerability

CVE.Org link: CVE-2025-3928 Save as PDF A vulnerability has been identified and remediated in all supported versions of the Commvault software. Webservers can be compromised through bad actors creating and executing webshells. Exploiting this vulnerability requires a bad actor to have authenticated user credentials within the Commvault Software environment. Unauthenticated access is not exploitable. For software customers, this means your environment must be: (i) accessible via the internet, (ii) compromised through an unrelated avenue, and (iii) accessed leveraging legitimate user credentials.

CVE-2025-3928
Unclassified
May 1, 2025
High7.8MS Server Exploited CISA KEV

High [CVE-2025-29824] Windows Common Log File System Driver Elevation of Privilege Vulnerability

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2025-29824
Windows Server
Apr 8, 2025
HighIvanti Exploited

High April Security Update

Ivanti’s vulnerability management program is a central part of our commitment to security. We employ rigorous testing and validation methodologies to enable swift identification, patching, and disclosure of vulnerabilities in collaboration with the broader security ecosystem. Our priority is to provide responsible and transparent communication to our customers, so they are empowered to defend their environments. In recent months, we have intensified our internal scanning, manual exploitation and testing capabilities, and have also made enhancements to our responsible disclosure process so that we promptly discover and address potential issues, and so that our customers are best equipped to take action. Ivanti releases standard security patches on the second Tuesday of every month. For many of our customers, the predictable schedule facilitates better planning and management of IT resources, allowing them to allocate time and personnel efficiently for the timely updates. Today, Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager (EPM). It is important for customers to know: We have no evidence of any of these vulnerabilities being exploited in the wild. These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in these Security Advisory.

Endpoint Manager
Apr 8, 2025
HighIvanti Exploited CISA KEV

High [CVE-2025-22457] Security Update: Pulse Connect Secure, Ivanti Connect Secure, Policy Secure and Neurons for ZTA Gateways

- * The following has been updated to make clear the vulnerability was fully patched in Ivanti Connect Secure 22.7R2.6 (released February 11, 2025). At Ivanti, our mission is to empower customers to defend their environments in an evolving and increasingly sophisticated threat landscape. Affected products named by the advisory: Policy Secure; Neurons for ZTA gateways.

CVE-2025-22457
Connect Secure (VPN)Policy SecureNeurons
Apr 3, 2025
High7.0MS Server Exploited CISA KEV

High [CVE-2025-26633] Microsoft Management Console Security Feature Bypass Vulnerability

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally. Affected products named by the advisory: Windows Server 2008 R2 Service Pack 1; Windows Server 2008 R2 Service Pack 1 (Server Core installation); Windows Server 2008 Service Pack 2; Windows Server 2008 Service Pack 2 (Server Core installation); and 12 more. Affected products named by the advisory: Windows Server 2012 (Server Core installation); Windows Server 2012 R2 (Server Core installation); Windows Server 2016 (Server Core installation); Windows Server 2019 (Server Core installation); and 2 more.

CVE-2025-26633
Windows Server
Mar 11, 2025
High8.2VMware Exploited CISA KEV

High [CVE-2025-22225] VMware ESXi contains an arbitrary write vulnerability

VMware ESXi contains an arbitrary write vulnerability. A malicious actor with privileges within the VMX process may trigger an arbitrary kernel write leading to an escape of the sandbox. Affected products named by the advisory: VMware Cloud Foundation; VMware Telco Cloud Platform; VMware Telco Cloud Infrastructure.

CVE-2025-22225
ESXiCloud Foundation
Mar 4, 2025
Critical9.6Vendor: HighFortinet Exploited CISA KEV

Critical [CVE-2024-55591 +1] Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.

CVE-2024-55591CVE-2025-24472
FortiGateFirewallFortiOSFortiProxy
Feb 11, 2025
UnratedSonicWall Exploited CISA KEV

Advisory [CVE-2025-23006] Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands

Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote unauthenticated attacker to execute arbitrary OS commands.

CVE-2025-23006
Unclassified
Jan 23, 2025