Skip to content

Commit be0fea9

Browse files
Update KEV: Thu Mar 27 00:11:54 UTC 2025
Signed-off-by: AboutCode Automation <[email protected]>
1 parent dd19c3c commit be0fea9

File tree

1 file changed

+37
-7
lines changed

1 file changed

+37
-7
lines changed

known_exploited_vulnerabilities.json

Lines changed: 37 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,39 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2025.03.24",
4-
"dateReleased": "2025-03-24T18:01:34.066Z",
5-
"count": 1308,
3+
"catalogVersion": "2025.03.26",
4+
"dateReleased": "2025-03-26T20:10:45.2111Z",
5+
"count": 1310,
66
"vulnerabilities": [
7+
{
8+
"cveID": "CVE-2019-9875",
9+
"vendorProject": "Sitecore",
10+
"product": "CMS and Experience Platform (XP)",
11+
"vulnerabilityName": "Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability",
12+
"dateAdded": "2025-03-26",
13+
"shortDescription": "Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.",
14+
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
15+
"dueDate": "2025-04-16",
16+
"knownRansomwareCampaignUse": "Unknown",
17+
"notes": "https:\/\/support.sitecore.com\/kb?id=kb_article_view&sysparm_article=KB0038556 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-9875",
18+
"cwes": [
19+
"CWE-502"
20+
]
21+
},
22+
{
23+
"cveID": "CVE-2019-9874",
24+
"vendorProject": "Sitecore",
25+
"product": "CMS and Experience Platform (XP)",
26+
"vulnerabilityName": "Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability",
27+
"dateAdded": "2025-03-26",
28+
"shortDescription": "Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending a serialized .NET object in the HTTP POST parameter __CSRFTOKEN.",
29+
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
30+
"dueDate": "2025-04-16",
31+
"knownRansomwareCampaignUse": "Unknown",
32+
"notes": "https:\/\/support.sitecore.com\/kb?id=kb_article_view&sysparm_article=KB0334035 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2019-9874",
33+
"cwes": [
34+
"CWE-502"
35+
]
36+
},
737
{
838
"cveID": "CVE-2025-30154",
939
"vendorProject": "reviewdog",
@@ -14,7 +44,7 @@
1444
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
1545
"dueDate": "2025-04-14",
1646
"knownRansomwareCampaignUse": "Unknown",
17-
"notes": "This vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: https:\/\/github.com\/reviewdog\/reviewdog\/security\/advisories\/GHSA-qmg3-hpqr-gqvc ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-30154",
47+
"notes": "This vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: CISA Mitigation Instructions: https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/03\/18\/supply-chain-compromise-third-party-tj-actionschanged-files-cve-2025-30066-and-reviewdogaction ; Additional References: https:\/\/github.com\/reviewdog\/reviewdog\/security\/advisories\/GHSA-qmg3-hpqr-gqvc ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-30154",
1848
"cwes": [
1949
"CWE-506"
2050
]
@@ -74,7 +104,7 @@
74104
"requiredAction": "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.",
75105
"dueDate": "2025-04-08",
76106
"knownRansomwareCampaignUse": "Unknown",
77-
"notes": "This vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: https:\/\/github.com\/tj-actions\/changed-files\/blob\/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73\/README.md?plain=1#L20-L28 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-30066",
107+
"notes": "This vulnerability affects a common open-source project, third-party library, or a protocol used by different products. For more information, please see: CISA Mitigation Instructions: https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/03\/18\/supply-chain-compromise-third-party-tj-actionschanged-files-cve-2025-30066-and-reviewdogaction ; Additional References: https:\/\/github.com\/tj-actions\/changed-files\/blob\/45fb12d7a8bedb4da42342e52fe054c6c2c3fd73\/README.md?plain=1#L20-L28 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-30066",
78108
"cwes": [
79109
"CWE-506"
80110
]
@@ -2964,7 +2994,7 @@
29642994
{
29652995
"cveID": "CVE-2024-4761",
29662996
"vendorProject": "Google",
2967-
"product": "Chromium Visuals",
2997+
"product": "Chromium V8",
29682998
"vulnerabilityName": "Google Chromium V8 Out-of-Bounds Memory Write Vulnerability",
29692999
"dateAdded": "2024-05-16",
29703000
"shortDescription": "Google Chromium V8 Engine contains an unspecified out-of-bounds memory write vulnerability via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. ",
@@ -14619,7 +14649,7 @@
1461914649
"cveID": "CVE-2020-6572",
1462014650
"vendorProject": "Google",
1462114651
"product": "Chrome Media",
14622-
"vulnerabilityName": "Google Chrome Media Prior to 81.0.4044.92 Use-After-Free Vulnerability",
14652+
"vulnerabilityName": "Google Chrome Media Use-After-Free Vulnerability",
1462314653
"dateAdded": "2022-01-10",
1462414654
"shortDescription": "Google Chrome Media contains a use-after-free vulnerability that allows a remote attacker to execute code via a crafted HTML page.",
1462514655
"requiredAction": "Apply updates per vendor instructions.",

0 commit comments

Comments
 (0)