Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

IONIX THREAT CENTER

A free, curated feed of CVEs that can be remotely exploited by an unauthenticated attacker, verified and published the moment they emerge. No noise, no triage backlog. Just the exploitable vulnerabilities that actually demand your attention, delivered in real time.

Be the first to know when new zero-days emerge:

Created Date
Source IONIX Threat Lab
CVE-2025-25257 Pre-Auth SQL Injection Leading to RCE In FortiWeb

An improper neutralization of special elements used in an SQL command in FortiWeb may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests. The vulnerability can be further escalated to a Remote Code Execution. The IONIX research team validated the impact through successful exploit reproduction, as detailed in this advisory.

Created Date
Source IONIX Threat Lab
CVE-2025-5777 – Memory Over Read in NetScaler Gateway

A critical vulnerability, CVE-2025-5777, has been identified in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. The flaw is a memory over-read caused by insufficient input validation, which can allow unauthenticated attackers to extract valid session tokens from memory. It affects multiple versions prior to 14.1-43.56 and 13.1-58.32.

Created Date
Source IONIX Threat Lab
CVE-2025-5349 – Improper Access Control in NetScaler Gateway

A high-severity vulnerability, CVE-2025-5349, has been identified in NetScaler ADC and NetScaler Gateway when the management interface is exposed via NSIP, Cluster Management IP, or site-local GSLB IP. The flaw stems from improper access control and may allow unauthorized users to access sensitive functionality without authentication. This impacts multiple versions prior to 14.1-43.56 and 13.1-58.32.

Created Date
Source IONIX Threat Lab
CVE-2025-6543 – Memory Overflow in NetScaler Gateway

A critical vulnerability, CVE-2025-6543, has been identified in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. This vulnerability is a memory overflow that may lead to unintended control flow and denial of service (DoS). It affects multiple versions prior to 14.1-47.46 and 13.1-59.19.

Created Date
Source IONIX Threat Lab
CVE-2025-30220 – Unauthenticated XML External Entity (XXE) in GeoServer

A critical vulnerability, CVE-2025-30220, has been identified in GeoServer’s Web Feature Service (WFS), impacting versions 2.27.0, 2.26.0 through 2.26.2, and all versions up to 2.25.6. The flaw originates from the underlying GeoTools library (gt-xsd-core), which mishandles XML parsing by bypassing the intended AllowListEntityResolver. This allows unauthenticated attackers to submit specially crafted XML payloads containing external entity definitions, leading to XML External Entity (XXE) injection.

Created Date
Source IONIX Threat Lab
CVE-2025-4009 – Remote Code Execution on Evertz devices

A critical vulnerability, CVE-2025-4009, has been identified in Evertz SDVN 3080ipx-10G and other devices leveraging the webEASY (ewb) management interface. This flaw affects all current versions and arises from a combination of an authentication bypass and unauthenticated command injection in administrative endpoints. By crafting a specially encoded JSON token, attackers can gain unauthorized administrative access.

Created Date
Source IONIX Threat Lab
CVE-2025-46701 – Improper Handling of Case Sensitivity lead to RCE on Apache Tomcat

A high-severity vulnerability, CVE-2025-46701, has been identified in Apache Tomcat, impacting versions 9.0.0.M1 to 9.0.104, 10.1.0-M1 to 10.1.40, and 11.0.0-M1 to 11.0.6. The issue stems from case-insensitive handling of the pathInfo component in CGI servlet mappings, allowing attackers to bypass security constraints by altering URI casing. Under certain conditions, this can lead to remote code execution (RCE).

Created Date
Source IONIX Threat Lab
CVE-2025-34027 Authentication Bypass on Versa Concerto

A critical vulnerability, CVE-2025-34027, has been identified in the Versa Concerto SD-WAN orchestration platform, affecting versions 12.1.2 through 12.2.0. This flaw results from a misconfiguration in the Traefik reverse proxy that enables authentication bypass, granting unauthorized access to administrative endpoints. Exploiting the vulnerable Spack upload endpoint, attackers can leverage a Time-of-Check to Time-of-Use (TOCTOU) race condition to manipulate file paths during load operations.

Created Date
Source IONIX Threat Lab
CVE-2025-4123 – Cross-Site Scripting (XSS) and Open Redirect in Grafana

A high-severity vulnerability, CVE-2025-4123, has been identified in Grafana (versions 8 and above), affecting both Grafana OSS and Grafana Enterprise. This flaw is a combination of an open redirect and path traversal within custom frontend plugin handling, enabling attackers to craft malicious links that redirect users to attacker-controlled sites and execute arbitrary JavaScript (XSS). If the vulnerable Grafana instance has anonymous access enabled, the attack does not require authentication.

Created Date
Source IONIX Threat Lab
CVE-2025-4428 & CVE-2025-4427 – Remote Code Execution at Ivanti EPMM

A critical remote code execution (RCE) chain, involving CVE-2025-4427 and CVE-2025-4428, has been identified in Ivanti Endpoint Manager Mobile (EPMM) versions up to 12.5.0.0. CVE-2025-4427 allows unauthenticated attackers to bypass authentication controls via the API component, granting access to otherwise protected resources. Chaining this with CVE-2025-4428, attackers with API access can craft malicious requests to execute arbitrary code on the underlying system.

Created Date
Source IONIX Threat Lab
CVE-2025-4396 – SQL Injection at Relevanssi (WordPress plugin)

A critical vulnerability, CVE-2025-4396, has been discovered in the Relevanssi – A Better Search plugin for WordPress, affecting all versions up to 4.24.4 (Free) and 2.27.4 (Premium). This flaw stems from insufficient input sanitization and improper SQL query preparation in handling the query parameters, enabling unauthenticated attackers to perform time-based SQL Injection. By exploiting this vulnerability, threat actors can append malicious SQL statements to existing queries, allowing them to extract sensitive data from the underlying WordPress database.

Created Date
Source IONIX Threat Lab
CVE-2025-2775 – Unauthenticated XML External Entity (XXE) vulnerability lead to RCE in SysAid

A critical vulnerability, CVE-2025-2775, has been identified in SysAid On-Prem versions ≤ 23.3.40, exposing the platform to an unauthenticated XML External Entity (XXE) injection flaw within the Checkin processing functionality. This vulnerability allows remote attackers to exploit XML parsing behavior to read arbitrary files from the server or gain access to sensitive information, including administrator credentials. Successful exploitation can lead to full administrative account takeover and further system compromise.

Created Date
Source IONIX Threat Lab
CVE-2025-31324 – Executable file upload vulnerability in SAP NetWeaver Application Server

A critical vulnerability, CVE-2025-31324, has been identified in SAP NetWeaver Visual Composer, allowing unauthenticated remote code execution via the Metadata Uploader component. This flaw arises from improper authentication checks, enabling attackers to send crafted HTTP/HTTPS requests to upload malicious binaries. Successful exploitation can result in complete system compromise.

Created Date
Source IONIX Threat Lab
CVE-2025-32433 – Remote Code Execution at Erlang/OTP

A critical vulnerability, CVE-2025-32433, has been discovered in the SSH server implementation within Erlang/OTP, allowing unauthenticated remote code execution through malformed SSH messages. This flaw arises from improper handling of protocol messages before authentication is completed, enabling attackers to send crafted payloads that the server processes unsafely. If the SSH daemon is running with elevated privileges, successful exploitation can result in complete system compromise.

Created Date
Source IONIX Threat Lab
CVE-2025-2825 – Authentication Bypass in CrushFTP

A critical vulnerability, CVE-2025-2825, has been identified in CrushFTP. This vulnerability allows remote unauthenticated access via specially crafted HTTP(S) requests, bypassing authentication checks through a flaw in the loginCheckHeaderAuth() method. It affects instances with S3-compatible API access enabled and can be exploited with knowledge of a valid username.

Created Date
Source IONIX Threat Lab
CVE-2025-2746 – Authentication Bypass in Kentico Xperience CMS

A critical authentication bypass vulnerability has been identified in Kentico Xperience CMS versions prior to 13.0.173. The vulnerability stems from an issue in the staging endpoint /CMSPages/Staging/SyncServer.asmx that allows attackers to forge requests and bypass authorization controls. This vulnerability can be exploited to gain full control over affected Xperience instances, specifically those with staging enabled and configured to use username and password authentication.

Created Date
Source IONIX Threat Lab
CVE-2025-2747 – Authentication Bypass in Kentico Xperience CMS

An authentication bypass vulnerability has been identified in Kentico Xperience CMS versions prior to 13.0.178. The vulnerability stems from a third-party library used by the product, allowing attackers to bypass the staging authentication mechanism. This issue affects only instances with staging enabled.

Created Date
Source IONIX Threat Lab
Multiple Remote Code Execution Vulnerabilities in Ingress NGINX Controller for Kubernetes

A series of critical vulnerabilities (CVE-2025-1974, CVE-2025-1097, CVE-2025-1098 and CVE-2025-24514) have been identified in the Ingress NGINX Controller for Kubernetes. These vulnerabilities allow unauthenticated remote code execution (RCE) via crafted requests to the Validating Admission Controller and admission controller components of ingress-nginx. Exploitation of these vulnerabilities can lead to unauthorized access to all secrets stored across all namespaces in the Kubernetes cluster, potentially resulting in a complete cluster takeover.

Created Date
Source IONIX Threat Lab
CVE-2025-24813 – Path Equivalence lead to Remote Code Execution in Apache Tomcat

A critical vulnerability, CVE-2025-24813, has been identified in Apache Tomcat. This vulnerability allows unauthenticated remote code execution (RCE) via crafted partial PUT requests, exploiting path equivalence issues in the default servlet when write permissions are enabled, and Tomcat's file based session persistence (FileStore), having both configured should be relatively rare, nonetheless, Tomcat's widespread. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98.

Created Date
Source IONIX Threat Lab
CVE-2025-24893 – Remote Code Execution in XWiki

A critical vulnerability, CVE-2025-24893, has been identified in XWiki Platform. This vulnerability allows unauthenticated remote code execution (RCE) via crafted requests to the SolrSearch endpoint, embedding Groovy script execution within the search query parameters. It impacts the confidentiality, integrity, and availability.

Created Date
Source IONIX Threat Lab
CVE-2025-0108 – Authentication Bypass in Palo Alto Networks PAN-OS

A critical vulnerability, CVE-2025-0108, has been identified in Palo Alto Networks PAN-OS, affecting versions 10.1.0 through 10.1.14, 10.2.0 through 10.2.13, 11.1.0 through 11.1.6, and 11.2.0 through 11.2.4. This vulnerability arises from an authentication bypass that allows an unauthenticated attacker with network access to the management web interface to circumvent authentication controls and invoke specific PHP scripts. While this flaw does not directly enable remote code execution (RCE), it significantly impacts the integrity and confidentiality of PAN-OS by exposing sensitive administrative functions.

Created Date
Source IONIX Threat Lab
CVE-2024-55591 – Authentication Bypass in FortiOS and FortiProxy

A critical Authentication Bypass vulnerability has been identified in FortiOS and FortiProxy, allowing remote attackers to gain super-admin privileges via crafted requests to the Node.js WebSocket module. Affected versions include FortiOS 7.0.0 through 7.0.16, FortiProxy 7.0.0 through 7.0.19, and FortiProxy 7.2.0 through 7.2.12. Reports indicate that this vulnerability is being actively exploited in the wild.

Created Date
Source IONIX Threat Lab
CVE-2024-50603 – Remote Code Execution in Aviatrix Controller

A critical vulnerability, CVE-2024-50603, has been identified in Aviatrix Controller versions prior to 7.1.4191 and 7.2.x versions prior to 7.2.4996. This vulnerability stems from the improper neutralization of special elements used in OS commands, allowing an unauthenticated attacker to execute arbitrary code. Exploitation is possible by sending shell metacharacters to the /v1/api endpoint in the cloud_type parameter for list_flightpath_destination_instances or the src_cloud_type parameter for flightpath_connection_test.

Created Date
Source IONIX Threat Lab
CVE-2025-0282 – Remote Code Execution in Ivanti

A critical vulnerability CVE-2025-0282 has been identified in Ivanti Connect Secure prior to 22.7R2.5, Ivanti Policy Secure prior to 22.7R1.2, and Ivanti Neurons for ZTA gateways prior to 22.7R2.3. The vulnerability is a stack-based buffer overflow that can lead to remote code execution (RCE). While no public exploit is currently available, there are reports of environments being targeted.

Created Date
Source IONIX Threat Lab
CVE-2024-52875 – Multiple vulnerabilities enable 1-Click RCE at Kerio Control

A critical vulnerability, CVE-2024-52875, has been identified in Kerio Control versions 9.2.5 through 9.4.5 including, affecting the security of systems using these versions. This vulnerability arises from two distinct issues: CRLF injection and Reflected Cross-Site Scripting (XSS), both caused by improper input sanitization on specific web pages. CRLF injection allows attackers to manipulate HTTP headers, which can lead to various response-splitting attacks, while XSS enables malicious scripts to execute in the context of a user's browser.

Created Date
Source IONIX Threat Lab
CVE-2024-55956 – File Upload Vulnerability In Cleo Harmony

In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.

Created Date
Source IONIX Threat Lab
Unauthenticated arbitrary file read in Mitel MiCollab (CVE has not been assigned yet)

The Mitel Collab Arbitrary File Read Vulnerability, combining CVE-2024-41713 and another yet-to-be-assigned issue, allows unauthenticated attackers to remotely and easily exploit the system to read arbitrary files from the underlying file system of a Mitel Collab server. By sending specially crafted requests, attackers can bypass access controls and retrieve sensitive files due to improper input validation and directory traversal flaws. To mitigate this vulnerability, follow the vendor advisory for CVE-2024-41713, ensuring the application properly validates and sanitizes user input to prevent directory traversal attacks.

Created Date
Source IONIX Threat Lab
CVE-2024-0012 – Authentication Bypass at Palo Alto Networks PAN-OS

An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities. The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended best practice deployment guidelines (see references) This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and…

Created Date
Source IONIX Threat Lab
CVE-2024-10924 – Authentication Bypass at Really Simple Security (WordPress plugin)

The Really Simple Security (Free, Pro, and Pro Multisite) plugin for WordPress is vulnerable to authentication bypass in versions 9.0.0 to 9.1.1.1 when the "Two-Factor Authentication" setting is enabled. This is due to improper user check error handling in the two-factor REST API actions with the 'check_login_and_get_user' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator.

Created Date
Source IONIX Threat Lab
CVE-2024-8068 and CVE-2024-8069: Citrix Session Recording Vulnerability (claimed to be RCE)

Citrix vulnerability (denoted as two issues: CVE-2024-8068 and CVE-2024-8069) is claimed to lead to unauthenticated remote code execution. According to the vendor, privilege escalation to NetworkService Account access in Citrix Session Recording and limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording is possible when an attacker is an authenticated user in the same intranet.

Created Date
Source IONIX Threat Lab
CVE-2024-47575 – FortiManager Remote Code Execution

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiManager Cloud 7.4.1 through 7.4.4, FortiManager Cloud 7.2.1 through 7.2.7, FortiManager Cloud 7.0.1 through 7.0.13, FortiManager Cloud 6.4.1 through 6.4.7 allows attacker to execute arbitrary code or commands via specially crafted requests.

Created Date
Source IONIX Threat Lab
CVE-2024-23113 – FortiOS Remote Code Execution

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSwitchManager versions 7.2.0 through 7.2.3, 7.0.0 through 7.0.3 allows attacker to execute unauthorized code or commands via specially crafted packets.

WATCH A SHORT IONIX DEMO

See how easy it is to implement a CTEM program with IONIX. Find and fix exploits fast.

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge