Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2025-6218
Known exploited
RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.
CVSS Score
7.8
EPSS Score
0.905
Published
2025-06-21
CVE-2025-5777
Known exploited
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
CVSS Score
9.3
EPSS Score
1.0
Published
2025-06-17
CVE-2025-43200
Known exploited
This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A logic issue existed when processing a maliciously crafted photo or video shared via an iCloud Link. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.
CVSS Score
4.2
EPSS Score
0.01
Published
2025-06-16
CVE-2025-33073
Known exploited
Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.
CVSS Score
8.8
EPSS Score
0.804
Published
2025-06-10
CVE-2025-33053
Known exploited
External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.
CVSS Score
8.8
EPSS Score
0.853
Published
2025-06-10
CVE-2025-47827
Known exploited
In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.
CVSS Score
4.6
EPSS Score
0.04
Published
2025-06-05
CVE-2025-21479
Known exploited
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVSS Score
8.6
EPSS Score
0.008
Published
2025-06-03
CVE-2025-27038
Known exploited
Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVSS Score
7.5
EPSS Score
0.008
Published
2025-06-03
CVE-2025-21480
Known exploited
Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.
CVSS Score
8.6
EPSS Score
0.004
Published
2025-06-03
CVE-2025-5419
Known exploited
Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVSS Score
8.8
EPSS Score
0.075
Published
2025-06-03


Contact Us

Shodan ® - All rights reserved