Loading HuntDB...

Known Exploited Vulnerabilities

Search through CISA's catalog of actively exploited vulnerabilities

Press Enter to search
190,224 vulnerabilities found
Showing 1 - 20

Linux Kernel Improper Ownership Management Vulnerability

Added June 17, 2025 CVE-2023-0386
Due Soon

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Linux Kernel
Due by July 8, 2025
Catalog 2025.06.17

Linux Kernel Improper Ownership Management Vulnerability

Added June 17, 2025 CVE-2023-0386
Due Soon

Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mapping bug allows a local user to escalate their privileges on the system.

Linux Kernel
Due by July 8, 2025
Catalog 2025.06.17

Apple Multiple Products Unspecified Vulnerability

Added June 16, 2025 CVE-2025-43200
Due Soon

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

Apple Multiple Products
Due by July 7, 2025
Catalog 2025.06.17

TP-Link Multiple Routers Command Injection Vulnerability

Added June 16, 2025 CVE-2023-33538
Due Soon

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

TP-Link Multiple Routers
Due by July 7, 2025
Catalog 2025.06.17

Apple Multiple Products Unspecified Vulnerability

Added June 16, 2025 CVE-2025-43200
Due Soon

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

Apple Multiple Products
Due by July 7, 2025
Catalog 2025.06.17

TP-Link Multiple Routers Command Injection Vulnerability

Added June 16, 2025 CVE-2023-33538
Due Soon

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

TP-Link Multiple Routers
Due by July 7, 2025
Catalog 2025.06.17

Apple Multiple Products Unspecified Vulnerability

Added June 16, 2025 CVE-2025-43200
Due Soon

Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.

Apple Multiple Products
Due by July 7, 2025
Catalog 2025.06.16

TP-Link Multiple Routers Command Injection Vulnerability

Added June 16, 2025 CVE-2023-33538
Due Soon

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

TP-Link Multiple Routers
Due by July 7, 2025
Catalog 2025.06.16

Wazuh Server Deserialization of Untrusted Data Vulnerability

Added June 10, 2025 CVE-2025-24016
Due Soon

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

Wazuh Wazuh Server
Due by July 1, 2025
Catalog 2025.06.17

Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

Added June 10, 2025 CVE-2025-33053
Due Soon

Web Distributed Authoring and Versioning (WebDAV) contains an external control of file name or path vulnerability. This vulnerability could allow an unauthorized attacker to execute code over a network. This vulnerability could affect various products that implement WebDAV, including but not limited to Microsoft Windows.

Web Distributed Authoring and Versioning Web Distributed Authoring and Versioning (WebDAV)
Due by July 1, 2025
Catalog 2025.06.17

Wazuh Server Deserialization of Untrusted Data Vulnerability

Added June 10, 2025 CVE-2025-24016
Due Soon

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

Wazuh Wazuh Server
Due by July 1, 2025
Catalog 2025.06.17

Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

Added June 10, 2025 CVE-2025-33053
Due Soon

Web Distributed Authoring and Versioning (WebDAV) contains an external control of file name or path vulnerability. This vulnerability could allow an unauthorized attacker to execute code over a network. This vulnerability could affect various products that implement WebDAV, including but not limited to Microsoft Windows.

Web Distributed Authoring and Versioning Web Distributed Authoring and Versioning (WebDAV)
Due by July 1, 2025
Catalog 2025.06.17

Wazuh Server Deserialization of Untrusted Data Vulnerability

Added June 10, 2025 CVE-2025-24016
Due Soon

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

Wazuh Wazuh Server
Due by July 1, 2025
Catalog 2025.06.16

Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

Added June 10, 2025 CVE-2025-33053
Due Soon

Web Distributed Authoring and Versioning (WebDAV) contains an external control of file name or path vulnerability. This vulnerability could allow an unauthorized attacker to execute code over a network. This vulnerability could affect various products that implement WebDAV, including but not limited to Microsoft Windows.

Web Distributed Authoring and Versioning Web Distributed Authoring and Versioning (WebDAV)
Due by July 1, 2025
Catalog 2025.06.16

Wazuh Server Deserialization of Untrusted Data Vulnerability

Added June 10, 2025 CVE-2025-24016
Due Soon

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

Wazuh Wazuh Server
Due by July 1, 2025
Catalog 2025.06.13

Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

Added June 10, 2025 CVE-2025-33053
Due Soon

Web Distributed Authoring and Versioning (WebDAV) contains an external control of file name or path vulnerability. This vulnerability could allow an unauthorized attacker to execute code over a network. This vulnerability could affect various products that implement WebDAV, including but not limited to Microsoft Windows.

Web Distributed Authoring and Versioning Web Distributed Authoring and Versioning (WebDAV)
Due by July 1, 2025
Catalog 2025.06.13

Wazuh Server Deserialization of Untrusted Data Vulnerability

Added June 10, 2025 CVE-2025-24016
Due Soon

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

Wazuh Wazuh Server
Due by July 1, 2025
Catalog 2025.06.13

Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

Added June 10, 2025 CVE-2025-33053
Due Soon

Web Distributed Authoring and Versioning (WebDAV) contains an external control of file name or path vulnerability. This vulnerability could allow an unauthorized attacker to execute code over a network. This vulnerability could affect various products that implement WebDAV, including but not limited to Microsoft Windows.

Web Distributed Authoring and Versioning Web Distributed Authoring and Versioning (WebDAV)
Due by July 1, 2025
Catalog 2025.06.13

Wazuh Server Deserialization of Untrusted Data Vulnerability

Added June 10, 2025 CVE-2025-24016
Due Soon

Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.

Wazuh Wazuh Server
Due by July 1, 2025
Catalog 2025.06.13

Web Distributed Authoring and Versioning (WebDAV) External Control of File Name or Path Vulnerability

Added June 10, 2025 CVE-2025-33053
Due Soon

Web Distributed Authoring and Versioning (WebDAV) contains an external control of file name or path vulnerability. This vulnerability could allow an unauthorized attacker to execute code over a network. This vulnerability could affect various products that implement WebDAV, including but not limited to Microsoft Windows.

Web Distributed Authoring and Versioning Web Distributed Authoring and Versioning (WebDAV)
Due by July 1, 2025
Catalog 2025.06.13