CVE-2025-66644
Array Networks · ArrayOS AG
Added Dec 8, 2025
Security Bulletins
Active threat advisories and known exploited vulnerabilities.
Pulled daily from the CISA Known Exploited Vulnerabilities catalog. Every entry has confirmed active exploitation in the wild. Last synced Jun 12, 2026.
Critical
Critical
CVE-2025-55182
Meta · React Server Components
Added Dec 5, 2025
Meta React Server Components Remote Code Execution Vulnerability
Critical
CVE-2021-26828
OpenPLC · ScadaBR
Added Dec 3, 2025
OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability
Critical
CVE-2025-48633
Android · Framework
Added Dec 2, 2025
Android Framework Information Disclosure Vulnerability
Critical
CVE-2025-48572
Android · Framework
Added Dec 2, 2025
Android Framework Privilege Escalation Vulnerability
Critical
CVE-2021-26829
OpenPLC · ScadaBR
Added Nov 28, 2025
OpenPLC ScadaBR Cross-site Scripting Vulnerability
Critical
CVE-2025-61757
Oracle · Fusion Middleware
Added Nov 21, 2025
Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability
Critical
CVE-2025-13223
Google · Chromium V8
Added Nov 19, 2025
Google Chromium V8 Type Confusion Vulnerability
Critical
CVE-2025-58034
Fortinet · FortiWeb
Added Nov 18, 2025
Fortinet FortiWeb OS Command Injection Vulnerability
Critical
CVE-2025-64446
Fortinet · FortiWeb
Added Nov 14, 2025
Fortinet FortiWeb Path Traversal Vulnerability
Critical
CVE-2025-12480
Gladinet · Triofox
Added Nov 12, 2025
Gladinet Triofox Improper Access Control Vulnerability
Critical
CVE-2025-62215
Microsoft · Windows
Added Nov 12, 2025
Microsoft Windows Race Condition Vulnerability
Critical
CVE-2025-9242
WatchGuard · Firebox
Added Nov 12, 2025
WatchGuard Firebox Out-of-Bounds Write Vulnerability
Critical
CVE-2025-21042
Samsung · Mobile Devices
Added Nov 10, 2025
Samsung Mobile Devices Out-of-Bounds Write Vulnerability
Critical
CVE-2025-48703
CWP · Control Web Panel
Added Nov 4, 2025
CWP Control Web Panel OS Command Injection Vulnerability
Critical
CVE-2025-11371
Gladinet · CentreStack and Triofox
Added Nov 4, 2025
Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability
Critical
CVE-2025-41244
Broadcom · VMware Aria Operations and VMware Tools
Added Oct 30, 2025
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Critical
CVE-2025-24893
XWiki · Platform
Added Oct 30, 2025
XWiki Platform Eval Injection Vulnerability
Critical
CVE-2025-6204
Dassault Systèmes · DELMIA Apriso
Added Oct 28, 2025
Dassault Systèmes DELMIA Apriso Code Injection Vulnerability
Critical
CVE-2025-6205
Dassault Systèmes · DELMIA Apriso
Added Oct 28, 2025
Dassault Systèmes DELMIA Apriso Missing Authorization Vulnerability
Critical
CVE-2025-59287
Microsoft · Windows
Added Oct 24, 2025
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Critical
CVE-2025-54236
Adobe · Commerce and Magento
Added Oct 24, 2025
Adobe Commerce and Magento Improper Input Validation Vulnerability
Critical
CVE-2025-61932
Motex · LANSCOPE Endpoint Manager
Added Oct 22, 2025
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
Critical
CVE-2025-61884
Oracle · E-Business Suite
Added Oct 20, 2025
Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability
Critical
CVE-2025-33073
Microsoft · Windows
Added Oct 20, 2025
Microsoft Windows SMB Client Improper Access Control Vulnerability
Need help prioritizing these vulnerabilities?
ThreatGrid can assess your environment and map active CVEs to your monitored assets.