Skip to content

Commit d262905

Browse files
Update KEV: Tue Feb 25 00:11:40 UTC 2025
Signed-off-by: AboutCode Automation <[email protected]>
1 parent b56eb21 commit d262905

File tree

1 file changed

+71
-41
lines changed

1 file changed

+71
-41
lines changed

known_exploited_vulnerabilities.json

Lines changed: 71 additions & 41 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,39 @@
11
{
22
"title": "CISA Catalog of Known Exploited Vulnerabilities",
3-
"catalogVersion": "2025.02.21",
4-
"dateReleased": "2025-02-21T17:07:48.4896Z",
5-
"count": 1276,
3+
"catalogVersion": "2025.02.24",
4+
"dateReleased": "2025-02-24T17:55:31.6365Z",
5+
"count": 1278,
66
"vulnerabilities": [
7+
{
8+
"cveID": "CVE-2024-20953",
9+
"vendorProject": "Oracle",
10+
"product": "Agile Product Lifecycle Management (PLM)",
11+
"vulnerabilityName": "Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability",
12+
"dateAdded": "2025-02-24",
13+
"shortDescription": "Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.",
14+
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
15+
"dueDate": "2025-03-17",
16+
"knownRansomwareCampaignUse": "Unknown",
17+
"notes": "https:\/\/www.oracle.com\/security-alerts\/cpujan2024.html ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-20953",
18+
"cwes": [
19+
"CWE-502"
20+
]
21+
},
22+
{
23+
"cveID": "CVE-2017-3066",
24+
"vendorProject": "Adobe",
25+
"product": "ColdFusion",
26+
"vulnerabilityName": "Adobe ColdFusion Deserialization Vulnerability",
27+
"dateAdded": "2025-02-24",
28+
"shortDescription": "Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.",
29+
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
30+
"dueDate": "2025-03-17",
31+
"knownRansomwareCampaignUse": "Unknown",
32+
"notes": "https:\/\/helpx.adobe.com\/security\/products\/coldfusion\/apsb17-14.html ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2017-3066",
33+
"cwes": [
34+
"CWE-502"
35+
]
36+
},
737
{
838
"cveID": "CVE-2025-24989",
939
"vendorProject": "Microsoft",
@@ -1348,10 +1378,10 @@
13481378
{
13491379
"cveID": "CVE-2024-45519",
13501380
"vendorProject": "Synacor",
1351-
"product": "Zimbra Collaboration",
1352-
"vulnerabilityName": "Synacor Zimbra Collaboration Command Execution Vulnerability",
1381+
"product": "Zimbra Collaboration Suite (ZCS)",
1382+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability",
13531383
"dateAdded": "2024-10-03",
1354-
"shortDescription": "Synacor Zimbra Collaboration contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.",
1384+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.",
13551385
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
13561386
"dueDate": "2024-10-24",
13571387
"knownRansomwareCampaignUse": "Unknown",
@@ -4435,11 +4465,11 @@
44354465
},
44364466
{
44374467
"cveID": "CVE-2023-37580",
4438-
"vendorProject": "Zimbra",
4439-
"product": "Collaboration (ZCS)",
4440-
"vulnerabilityName": "Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability",
4468+
"vendorProject": "Synacor",
4469+
"product": "Zimbra Collaboration Suite (ZCS)",
4470+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
44414471
"dateAdded": "2023-07-27",
4442-
"shortDescription": "Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.",
4472+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability impacting the confidentiality and integrity of data.",
44434473
"requiredAction": "Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.",
44444474
"dueDate": "2023-08-17",
44454475
"knownRansomwareCampaignUse": "Unknown",
@@ -5530,11 +5560,11 @@
55305560
},
55315561
{
55325562
"cveID": "CVE-2022-27926",
5533-
"vendorProject": "Zimbra",
5534-
"product": "Collaboration (ZCS)",
5535-
"vulnerabilityName": "Zimbra Collaboration (ZCS) Cross-Site Scripting (XSS) Vulnerability",
5563+
"vendorProject": "Synacor",
5564+
"product": "Zimbra Collaboration Suite (ZCS)",
5565+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
55365566
"dateAdded": "2023-04-03",
5537-
"shortDescription": "Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.",
5567+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.",
55385568
"requiredAction": "Apply updates per vendor instructions.",
55395569
"dueDate": "2023-04-24",
55405570
"knownRansomwareCampaignUse": "Unknown",
@@ -6505,11 +6535,11 @@
65056535
},
65066536
{
65076537
"cveID": "CVE-2022-41352",
6508-
"vendorProject": "Zimbra",
6509-
"product": "Collaboration (ZCS)",
6510-
"vulnerabilityName": "Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability",
6538+
"vendorProject": "Synacor",
6539+
"product": "Zimbra Collaboration Suite (ZCS)",
6540+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability",
65116541
"dateAdded": "2022-10-20",
6512-
"shortDescription": "Zimbra Collaboration (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.",
6542+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.",
65136543
"requiredAction": "Apply updates per vendor instructions.",
65146544
"dueDate": "2022-11-10",
65156545
"knownRansomwareCampaignUse": "Unknown",
@@ -7201,11 +7231,11 @@
72017231
},
72027232
{
72037233
"cveID": "CVE-2022-27925",
7204-
"vendorProject": "Zimbra",
7205-
"product": "Collaboration (ZCS)",
7206-
"vulnerabilityName": "Zimbra Collaboration (ZCS) Arbitrary File Upload Vulnerability",
7234+
"vendorProject": "Synacor",
7235+
"product": "Zimbra Collaboration Suite (ZCS)",
7236+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability",
72077237
"dateAdded": "2022-08-11",
7208-
"shortDescription": "Zimbra Collaboration (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.",
7238+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.",
72097239
"requiredAction": "Apply updates per vendor instructions.",
72107240
"dueDate": "2022-09-01",
72117241
"knownRansomwareCampaignUse": "Unknown",
@@ -7216,11 +7246,11 @@
72167246
},
72177247
{
72187248
"cveID": "CVE-2022-37042",
7219-
"vendorProject": "Zimbra",
7220-
"product": "Collaboration (ZCS)",
7221-
"vulnerabilityName": "Zimbra Collaboration (ZCS) Authentication Bypass Vulnerability",
7249+
"vendorProject": "Synacor",
7250+
"product": "Zimbra Collaboration Suite (ZCS)",
7251+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability",
72227252
"dateAdded": "2022-08-11",
7223-
"shortDescription": "Zimbra Collaboration (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.",
7253+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.",
72247254
"requiredAction": "Apply updates per vendor instructions.",
72257255
"dueDate": "2022-09-01",
72267256
"knownRansomwareCampaignUse": "Unknown",
@@ -7260,11 +7290,11 @@
72607290
},
72617291
{
72627292
"cveID": "CVE-2022-27924",
7263-
"vendorProject": "Zimbra",
7264-
"product": "Collaboration (ZCS)",
7265-
"vulnerabilityName": "Zimbra Collaboration (ZCS) Command Injection Vulnerability",
7293+
"vendorProject": "Synacor",
7294+
"product": "Zimbra Collaboration Suite (ZCS)",
7295+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability",
72667296
"dateAdded": "2022-08-04",
7267-
"shortDescription": "Zimbra Collaboration (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.",
7297+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.",
72687298
"requiredAction": "Apply updates per vendor instructions.",
72697299
"dueDate": "2022-08-25",
72707300
"knownRansomwareCampaignUse": "Unknown",
@@ -9357,11 +9387,11 @@
93579387
},
93589388
{
93599389
"cveID": "CVE-2018-6882",
9360-
"vendorProject": "Zimbra",
9361-
"product": "Collaboration Suite (ZCS)",
9362-
"vulnerabilityName": "Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
9390+
"vendorProject": "Synacor",
9391+
"product": "Zimbra Collaboration Suite (ZCS)",
9392+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
93639393
"dateAdded": "2022-04-19",
9364-
"shortDescription": "Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.",
9394+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that might allow remote attackers to inject arbitrary web script or HTML.",
93659395
"requiredAction": "Apply updates per vendor instructions.",
93669396
"dueDate": "2022-05-10",
93679397
"knownRansomwareCampaignUse": "Known",
@@ -13255,11 +13285,11 @@
1325513285
},
1325613286
{
1325713287
"cveID": "CVE-2022-24682",
13258-
"vendorProject": "Zimbra",
13259-
"product": "Webmail",
13260-
"vulnerabilityName": "Zimbra Webmail Cross-Site Scripting Vulnerability",
13288+
"vendorProject": "Synacor",
13289+
"product": "Zimbra Webmail",
13290+
"vulnerabilityName": "Synacor Zimbra Webmail Cross-Site Scripting Vulnerability",
1326113291
"dateAdded": "2022-02-25",
13262-
"shortDescription": "Zimbra webmail clients running versions 8.8.15 P29 & P30 contain a XSS vulnerability that would allow attackers to steal session cookie files.",
13292+
"shortDescription": "Synacor Zimbra webmail clients running versions 8.8.15 P29 & P30 contain a XSS vulnerability that would allow attackers to steal session cookie files.",
1326313293
"requiredAction": "Apply updates per vendor instructions.",
1326413294
"dueDate": "2022-03-11",
1326513295
"knownRansomwareCampaignUse": "Known",
@@ -14195,10 +14225,10 @@
1419514225
{
1419614226
"cveID": "CVE-2019-9670",
1419714227
"vendorProject": "Synacor",
14198-
"product": "Zimbra Collaboration (ZCS)",
14199-
"vulnerabilityName": "Synacor Zimbra Collaboration (ZCS) Improper Restriction of XML External Entity Reference",
14228+
"product": "Zimbra Collaboration Suite (ZCS)",
14229+
"vulnerabilityName": "Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference",
1420014230
"dateAdded": "2022-01-10",
14201-
"shortDescription": "Improper Restriction of XML External Entity Reference vulnerability affecting Synacor Zimbra Collaboration (ZCS).",
14231+
"shortDescription": "Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.",
1420214232
"requiredAction": "Apply updates per vendor instructions.",
1420314233
"dueDate": "2022-07-10",
1420414234
"knownRansomwareCampaignUse": "Unknown",

0 commit comments

Comments
 (0)