{"@context":{"@vocab":"https://schema.org/","dcterms":"http://purl.org/dc/terms/","prov":"http://www.w3.org/ns/prov#"},"@type":"ItemList","@id":"https://api.ai-analytics.org/api/v1/cisa/kev/recent","_source":{"data_provider":"AI Analytics","data_provider_url":"https://api.ai-analytics.org","license":"https://creativecommons.org/publicdomain/zero/1.0/","dcterms:license":"https://creativecommons.org/publicdomain/zero/1.0/","generated_at":"2026-09-13T02:45:22.738Z","primary_source":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"},"filter":{"vendor":null,"ransomware":"Known"},"count":50,"items":[{"cve_id":"CVE-2026-59310","vendor_project":"Broadcom","product":"VMware vCenter","vulnerability_name":"Broadcom VMware vCenter Path Traversal Vulnerability","date_added":"2026-08-18","due_date":"2026-08-21","known_ransomware_use":"Known","description":"Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59310"},{"cve_id":"CVE-2026-20316","vendor_project":"Cisco","product":"Secure Firewall Management Center (FMC)","vulnerability_name":"Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability","date_added":"2026-07-29","due_date":"2026-08-01","known_ransomware_use":"Known","description":"Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20316"},{"cve_id":"CVE-2026-15409","vendor_project":"SonicWall","product":"SMA1000 Appliances","vulnerability_name":"SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability","date_added":"2026-07-14","due_date":"2026-07-17","known_ransomware_use":"Known","description":"SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15409"},{"cve_id":"CVE-2026-15410","vendor_project":"SonicWall","product":"SMA1000 Appliances","vulnerability_name":"SonicWall SMA1000 Appliances Code Injection Vulnerability","date_added":"2026-07-14","due_date":"2026-07-17","known_ransomware_use":"Known","description":"SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-15410"},{"cve_id":"CVE-2026-45659","vendor_project":"Microsoft","product":"SharePoint Server","vulnerability_name":"Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability","date_added":"2026-07-01","due_date":"2026-07-04","known_ransomware_use":"Known","description":"Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45659"},{"cve_id":"CVE-2026-12569","vendor_project":"PTC","product":"Windchill and FlexPLM","vulnerability_name":"PTC Windchill and FlexPLM Improper Input Validation Vulnerability","date_added":"2026-06-25","due_date":"2026-06-28","known_ransomware_use":"Known","description":"PTC Windchill and FlexPLM contains an improper input validation vulnerability allowing an unauthenticated, remote attacker to execute arbitrary code by sending a malicious request to the network.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12569"},{"cve_id":"CVE-2026-35273","vendor_project":"Oracle","product":" PeopleSoft Enterprise PeopleTools","vulnerability_name":"Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability","date_added":"2026-06-12","due_date":"2026-06-15","known_ransomware_use":"Known","description":"Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35273"},{"cve_id":"CVE-2026-50751","vendor_project":"Check Point","product":"Security Gateway","vulnerability_name":"Check Point Security Gateway Improper Authentication Vulnerability","date_added":"2026-06-08","due_date":"2026-06-11","known_ransomware_use":"Known","description":"Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user p","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50751"},{"cve_id":"CVE-2026-0257","vendor_project":"Palo Alto Networks","product":"PAN-OS","vulnerability_name":"Palo Alto Networks PAN-OS Authentication Bypass Vulnerability","date_added":"2026-05-29","due_date":"2026-06-01","known_ransomware_use":"Known","description":"Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0257"},{"cve_id":"CVE-2026-48027","vendor_project":"Nx","product":"Nx Console","vulnerability_name":"Nx Console Embedded Malicious Code Vulnerability","date_added":"2026-05-27","due_date":"2026-06-10","known_ransomware_use":"Known","description":"Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48027"},{"cve_id":"CVE-2026-45321","vendor_project":"TanStack","product":"TanStack","vulnerability_name":"TanStack Unspecified Vulnerability","date_added":"2026-05-27","due_date":"2026-06-10","known_ransomware_use":"Known","description":"TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45321"},{"cve_id":"CVE-2026-41940","vendor_project":"WebPros","product":"cPanel & WHM and WP2 (WordPress Squared)","vulnerability_name":"WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability","date_added":"2026-04-30","due_date":"2026-05-03","known_ransomware_use":"Known","description":"WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared) contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41940"},{"cve_id":"CVE-2024-1708","vendor_project":"ConnectWise","product":"ScreenConnect","vulnerability_name":"ConnectWise ScreenConnect Path Traversal Vulnerability","date_added":"2026-04-28","due_date":"2026-05-12","known_ransomware_use":"Known","description":"ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-1708"},{"cve_id":"CVE-2024-57728","vendor_project":"SimpleHelp ","product":"SimpleHelp","vulnerability_name":"SimpleHelp Path Traversal Vulnerability","date_added":"2026-04-24","due_date":"2026-05-08","known_ransomware_use":"Known","description":"SimpleHelp contains a path traversal vulnerability that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the conte","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-57728"},{"cve_id":"CVE-2024-57726","vendor_project":"SimpleHelp ","product":"SimpleHelp","vulnerability_name":"SimpleHelp Missing Authorization Vulnerability","date_added":"2026-04-24","due_date":"2026-05-08","known_ransomware_use":"Known","description":"SimpleHelp contains a missing authorization vulnerability that could allow low-privileged technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-57726"},{"cve_id":"CVE-2026-33825","vendor_project":"Microsoft","product":"Defender","vulnerability_name":"Microsoft Defender Insufficient Granularity of Access Control Vulnerability","date_added":"2026-04-22","due_date":"2026-05-06","known_ransomware_use":"Known","description":"Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33825"},{"cve_id":"CVE-2023-27351","vendor_project":"PaperCut","product":"NG/MF","vulnerability_name":"PaperCut NG/MF Improper Authentication Vulnerability","date_added":"2026-04-20","due_date":"2026-05-04","known_ransomware_use":"Known","description":"PaperCut NG/MF contains an improper authentication vulnerability that could allow remote attackers to bypass authentication on affected installations via the SecurityRequestFilter class.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2023-27351"},{"cve_id":"CVE-2024-27199","vendor_project":"JetBrains","product":"TeamCity","vulnerability_name":"JetBrains TeamCity Relative Path Traversal Vulnerability","date_added":"2026-04-20","due_date":"2026-05-04","known_ransomware_use":"Known","description":"JetBrains TeamCity contains a relative path traversal vulnerability that could allow limited admin actions to be performed.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27199"},{"cve_id":"CVE-2025-60710","vendor_project":"Microsoft","product":"Windows","vulnerability_name":"Microsoft Windows Link Following Vulnerability","date_added":"2026-04-13","due_date":"2026-04-27","known_ransomware_use":"Known","description":"Microsoft Windows contains a link following vulnerability that allows for privilege escalation","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-60710"},{"cve_id":"CVE-2023-21529","vendor_project":"Microsoft","product":"Exchange Server","vulnerability_name":"Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability","date_added":"2026-04-13","due_date":"2026-04-27","known_ransomware_use":"Known","description":"Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2023-21529"},{"cve_id":"CVE-2026-20131","vendor_project":"Cisco","product":"Secure Firewall Management Center (FMC)","vulnerability_name":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability","date_added":"2026-03-19","due_date":"2026-03-22","known_ransomware_use":"Known","description":"Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, rem","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-20131"},{"cve_id":"CVE-2025-26399","vendor_project":"SolarWinds","product":"Web Help Desk","vulnerability_name":"SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability","date_added":"2026-03-09","due_date":"2026-03-12","known_ransomware_use":"Known","description":"SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26399"},{"cve_id":"CVE-2026-1731","vendor_project":"BeyondTrust","product":"Remote Support (RS) and Privileged Remote Access (PRA)","vulnerability_name":"BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability","date_added":"2026-02-13","due_date":"2026-02-16","known_ransomware_use":"Known","description":"BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site us","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-1731"},{"cve_id":"CVE-2026-24423","vendor_project":"SmarterTools","product":"SmarterMail","vulnerability_name":"SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability","date_added":"2026-02-05","due_date":"2026-02-26","known_ransomware_use":"Known","description":"SmarterTools SmarterMail contains a missing authentication for critical function vulnerability in the ConnectToHub API method. This could allow the attacker to point the SmarterMail instance to a malicious HTTP server which serves the malicious OS co","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24423"},{"cve_id":"CVE-2025-52691","vendor_project":"SmarterTools","product":"SmarterMail","vulnerability_name":"SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability","date_added":"2026-01-26","due_date":"2026-02-16","known_ransomware_use":"Known","description":"SmarterTools SmarterMail contains an unrestricted upload of file with dangerous type vulnerability that could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52691"},{"cve_id":"CVE-2026-23760","vendor_project":"SmarterTools","product":"SmarterMail","vulnerability_name":"SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability","date_added":"2026-01-26","due_date":"2026-02-16","known_ransomware_use":"Known","description":"SmarterTools SmarterMail contains an authentication bypass using an alternate path or channel vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset t","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23760"},{"cve_id":"CVE-2025-14733","vendor_project":"WatchGuard","product":"Firebox","vulnerability_name":"WatchGuard Firebox Out of Bounds Write Vulnerability","date_added":"2025-12-19","due_date":"2025-12-26","known_ransomware_use":"Known","description":"WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and affects both the mobile user VPN with IKEv2 and the","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14733"},{"cve_id":"CVE-2025-55182","vendor_project":"Meta","product":"React Server Components","vulnerability_name":"Meta React Server Components Remote Code Execution Vulnerability","date_added":"2025-12-05","due_date":"2025-12-12","known_ransomware_use":"Known","description":"Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Server Function endpoints. Please note CVE-2025-66478 ","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55182"},{"cve_id":"CVE-2025-61884","vendor_project":"Oracle","product":"E-Business Suite","vulnerability_name":"Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability","date_added":"2025-10-20","due_date":"2025-11-10","known_ransomware_use":"Known","description":"Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61884"},{"cve_id":"CVE-2021-43226","vendor_project":"Microsoft","product":"Windows","vulnerability_name":"Microsoft Windows Privilege Escalation Vulnerability","date_added":"2025-10-06","due_date":"2025-10-27","known_ransomware_use":"Known","description":"Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43226"},{"cve_id":"CVE-2025-61882","vendor_project":"Oracle","product":"E-Business Suite","vulnerability_name":"Oracle E-Business Suite Unspecified Vulnerability","date_added":"2025-10-06","due_date":"2025-10-27","known_ransomware_use":"Known","description":"Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61882"},{"cve_id":"CVE-2025-10035","vendor_project":"Fortra","product":"GoAnywhere MFT","vulnerability_name":"Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability","date_added":"2025-09-29","due_date":"2025-10-20","known_ransomware_use":"Known","description":"Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10035"},{"cve_id":"CVE-2025-8088","vendor_project":"RARLAB","product":"WinRAR","vulnerability_name":"RARLAB WinRAR Path Traversal Vulnerability","date_added":"2025-08-12","due_date":"2025-09-02","known_ransomware_use":"Known","description":"RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-8088"},{"cve_id":"CVE-2025-49704","vendor_project":"Microsoft","product":"SharePoint","vulnerability_name":"Microsoft SharePoint Code Injection Vulnerability","date_added":"2025-07-22","due_date":"2025-07-23","known_ransomware_use":"Known","description":"Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49704"},{"cve_id":"CVE-2025-49706","vendor_project":"Microsoft","product":"SharePoint","vulnerability_name":"Microsoft SharePoint Improper Authentication Vulnerability","date_added":"2025-07-22","due_date":"2025-07-23","known_ransomware_use":"Known","description":"Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to dis","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-49706"},{"cve_id":"CVE-2025-53770","vendor_project":"Microsoft","product":"SharePoint","vulnerability_name":"Microsoft SharePoint Deserialization of Untrusted Data Vulnerability","date_added":"2025-07-20","due_date":"2025-07-21","known_ransomware_use":"Known","description":"Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a ","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-53770"},{"cve_id":"CVE-2025-5777","vendor_project":"Citrix","product":"NetScaler ADC and Gateway","vulnerability_name":"Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability","date_added":"2025-07-10","due_date":"2025-07-11","known_ransomware_use":"Known","description":"Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP ","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5777"},{"cve_id":"CVE-2019-6693","vendor_project":"Fortinet","product":"FortiOS","vulnerability_name":"Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability","date_added":"2025-06-25","due_date":"2025-07-16","known_ransomware_use":"Known","description":"Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key. ","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6693"},{"cve_id":"CVE-2025-42999","vendor_project":"SAP","product":"NetWeaver","vulnerability_name":"SAP NetWeaver Deserialization Vulnerability","date_added":"2025-05-15","due_date":"2025-06-05","known_ransomware_use":"Known","description":"SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious conte","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-42999"},{"cve_id":"CVE-2025-3248","vendor_project":"Langflow","product":"Langflow","vulnerability_name":"Langflow Missing Authentication Vulnerability","date_added":"2025-05-05","due_date":"2025-05-26","known_ransomware_use":"Known","description":"Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3248"},{"cve_id":"CVE-2025-31324","vendor_project":"SAP","product":"NetWeaver","vulnerability_name":"SAP NetWeaver Unrestricted File Upload Vulnerability","date_added":"2025-04-29","due_date":"2025-05-20","known_ransomware_use":"Known","description":"SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-31324"},{"cve_id":"CVE-2025-29824","vendor_project":"Microsoft","product":"Windows","vulnerability_name":"Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability","date_added":"2025-04-08","due_date":"2025-04-29","known_ransomware_use":"Known","description":"Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-29824"},{"cve_id":"CVE-2025-31161","vendor_project":"CrushFTP","product":"CrushFTP","vulnerability_name":"CrushFTP Authentication Bypass Vulnerability","date_added":"2025-04-07","due_date":"2025-04-28","known_ransomware_use":"Known","description":"CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., crushadmin), potentially leading to a full compromis","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-31161"},{"cve_id":"CVE-2025-22457","vendor_project":"Ivanti","product":"Connect Secure, Policy Secure, and ZTA Gateways","vulnerability_name":"Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability","date_added":"2025-04-04","due_date":"2025-04-11","known_ransomware_use":"Known","description":"Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. ","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22457"},{"cve_id":"CVE-2025-24472","vendor_project":"Fortinet","product":"FortiOS and FortiProxy","vulnerability_name":"Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability","date_added":"2025-03-18","due_date":"2025-04-08","known_ransomware_use":"Known","description":" Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24472"},{"cve_id":"CVE-2025-26633","vendor_project":"Microsoft","product":"Windows","vulnerability_name":"Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability","date_added":"2025-03-11","due_date":"2025-04-01","known_ransomware_use":"Known","description":"Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-26633"},{"cve_id":"CVE-2025-22225","vendor_project":"VMware","product":"ESXi","vulnerability_name":"VMware ESXi Arbitrary Write Vulnerability","date_added":"2025-03-04","due_date":"2025-03-25","known_ransomware_use":"Known","description":"VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of the sandbox.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2025-22225"},{"cve_id":"CVE-2018-8639","vendor_project":"Microsoft","product":"Windows","vulnerability_name":"Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability","date_added":"2025-03-03","due_date":"2025-03-24","known_ransomware_use":"Known","description":"Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2018-8639"},{"cve_id":"CVE-2024-53704","vendor_project":"SonicWall","product":"SonicOS","vulnerability_name":"SonicWall SonicOS SSLVPN Improper Authentication Vulnerability","date_added":"2025-02-18","due_date":"2025-03-11","known_ransomware_use":"Known","description":"SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53704"},{"cve_id":"CVE-2024-57727","vendor_project":"SimpleHelp ","product":"SimpleHelp","vulnerability_name":"SimpleHelp Path Traversal Vulnerability","date_added":"2025-02-13","due_date":"2025-03-06","known_ransomware_use":"Known","description":"SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configurati","nvd_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-57727"}]}