Live
Last updated:

Cybersecurity Intelligence Center

Known Exploits, CVEs & Patch Alerts - Updated Daily

Critical CVEs

3

Known Exploits

3

Patch Alerts

3

Last Updated

Today

Latest CVEs (Updated Daily)

CVE-2025-0001

Critical
CVSS:9.8
Exploit AvailablePatch Available

Critical Remote Code Execution in Apache HTTP Server

A critical vulnerability in Apache HTTP Server allows remote attackers to execute arbitrary code through malformed HTTP requests.

Vendor:

Apache Software Foundation

Product:

HTTP Server

Versions:

2.4.0 - 2.4.58

Published:

2025-01-28

CVE-2025-0002

High
CVSS:8.8
Exploit AvailablePatch Available

Windows Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists in Windows Kernel that allows attackers to gain SYSTEM privileges.

Vendor:

Microsoft

Product:

Windows

Versions:

Windows 10, Windows 11, Windows Server 2019/2022

Published:

2025-01-27

CVE-2025-0003

Critical
CVSS:9.1
Exploit AvailablePatch Available

Critical SQL Injection in Popular CMS Platform

Multiple SQL injection vulnerabilities in WordPress plugin allow remote attackers to extract sensitive database information.

Vendor:

WordPress

Product:

Popular Plugin

Versions:

1.0 - 3.2.1

Published:

2025-01-26

CVE-2025-0004

High
CVSS:8.8
Patch Available

Chrome V8 Engine Use-After-Free Vulnerability

A use-after-free vulnerability in Chrome's V8 JavaScript engine allows remote code execution through crafted web pages.

Vendor:

Google

Product:

Chrome

Versions:

120.0 - 121.0.6166.0

Published:

2025-01-25

CVE-2025-0005

Critical
CVSS:9.8
Patch Available

Critical Vulnerability in OpenSSL Library

A buffer overflow vulnerability in OpenSSL allows remote attackers to cause denial of service or potentially execute code.

Vendor:

OpenSSL Project

Product:

OpenSSL

Versions:

3.0.0 - 3.2.0

Published:

2025-01-24

CISA Known Exploited Vulnerabilities

CVE-2024-12345

CriticalActive Exploitation

Citrix NetScaler ADC Remote Code Execution

Citrix NetScaler ADC contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands.

Vendor:

Citrix

Product:

NetScaler ADC

Due Date:

2025-02-18

Required Action: Apply updates per vendor instructions

Note: This vulnerability is being actively exploited in the wild

CVE-2024-54321

CriticalActive Exploitation

VMware vCenter Server Authentication Bypass

VMware vCenter Server contains an authentication bypass vulnerability allowing attackers to gain administrative access.

Vendor:

VMware

Product:

vCenter Server

Due Date:

2025-02-17

Required Action: Apply security patches immediately

Note: Active exploitation observed by multiple threat actors

CVE-2024-98765

HighActive Exploitation

Fortinet FortiOS Path Traversal Vulnerability

Fortinet FortiOS contains a path traversal vulnerability that allows attackers to read arbitrary files from the system.

Vendor:

Fortinet

Product:

FortiOS

Due Date:

2025-02-16

Required Action: Update to latest firmware version

Note: Exploitation attempts detected globally

Security Patch Alerts

Microsoft January 2025 Patch Tuesday

Critical
2025-01-14

Microsoft releases security updates addressing 89 vulnerabilities, including 12 critical flaws affecting Windows and Office.

12

Critical

45

High

32

Medium

Affected Products:
Windows 10Windows 11Office 365Exchange Server
KB Articles:
KB5034441KB5034442KB5034443

Adobe Emergency Security Update

Critical
2025-01-20

Adobe releases out-of-band security updates for Acrobat and Reader addressing actively exploited zero-day vulnerabilities.

3

Critical

2

High

1

Medium

Affected Products:
Acrobat DCAcrobat Reader DC
KB Articles:
APSB25-01

Google Chrome Security Update

High
2025-01-18

Google releases Chrome 121.0.6167.85 addressing multiple high-severity vulnerabilities in V8 engine and renderer.

0

Critical

8

High

4

Medium

Affected Products:
Chrome BrowserChrome OS
KB Articles:
121.0.6167.85